Suspicious
Suspect

PE Executable
MD5: 8790c67fe71c539809fca68373f753d6
Size: 722.94 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 8790c67fe71c539809fca68373f753d6
Sha1 b7b65ba843a6d19110a8865752ea6cfc8478f76b
Sha256 57fd4666f5ee7b31e8b02f6c31d0a33bb08f5eb1694a759b0b1aa95ec9fc0524
Sha384 f84962d1646925eea5bb5dcadaa99df8bc62735210a5f6cf716d2d9d51ec3d5e7947c89b1013627cc27ca58ce2eb0175
Sha512 f6932081cf88075227666888bab33be3b4e42bc824ccb853e6945dd0aa8520fdfa345b6ee84cf642753bb696458810b41e74ea82377fea892edd6a4e47a665d6
SSDeep 12288:LOBXJx9wtKBsPhglthJsgfgUZUwHYwc/+OyXvC6r/f/5ki3ErTm7cZF1RA9MGTaZ:LyBE5gljJTRZzr/35ki3E3mu1RpGWFka
TLSH E1F401486667DB52DDE50BF41A30D13103B7ADDEA811D30B8EEAFCEB7C2075428A5297
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModernAdapter.MainForm.resources
ModernAdapter.Properties.Resources.resources
FCmn
SL
Name Value
Module Name
glUO.exe
Full Name
glUO.exe
EntryPoint
System.Void ModernAdapter.Program::Main()
Scope Name
glUO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
glUO
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
617
Main Method
System.Void ModernAdapter.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void ModernAdapter.Program::InitializeApplication()
nop <null>
newobj System.Void ModernAdapter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
glUO.exe
Full Name
glUO.exe
EntryPoint
System.Void ModernAdapter.Program::Main()
Scope Name
glUO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
glUO
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
617
Main Method
System.Void ModernAdapter.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void ModernAdapter.Program::InitializeApplication()
nop <null>
newobj System.Void ModernAdapter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModernAdapter.MainForm.resources
ModernAdapter.Properties.Resources.resources
FCmn
SL
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
8790c67fe71c539809fca68373f753d6
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
8790c67fe71c539809fca68373f753d6
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙