Suspicious
Suspect

886b631945d235789db69511abd76d99

PE Executable
MD5: 886b631945d235789db69511abd76d99
Size: 755.71 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 886b631945d235789db69511abd76d99
Sha1 5b74ac76b42210cdab8e73ad49e8cf3abd1ba026
Sha256 bdb77fb15a71d15824003e2baca520124dab19ec99a1cd90e12769be216e1541
Sha384 655a701f8bc338b651e879b017e206b7bd9c191b48cd95b958b8389b35a3c38bddc6841b2d45e2ff5a2b74fbc682edac
Sha512 0940f56b7dba75ad348f956a3395066b58657215a29b664719896abb4c326a2344384634d9f3f54ee7f58a01a95ca9fc8e9c8cb40092b09d0adbc9f7fa992a09
SSDeep 12288:+BBf7Wr2/j5EGEScyesTfzx/aeB6HNI2wwbnaLhk2TXIrKIT:+vf7WcuYcoZ5BWJwSnaLhkQFI
TLSH 54F412486B1BDD12DCC51FB14CA0E37612349E5CE420C61B8BEDADEBB47AF6539192C2
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
testeMatematico.Form1.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
CHT
[NBF]root.Data
timer1.TrayLocation
testeMatematico.Properties.Resources.resources
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
ftcl
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
UBoo.exe
Full Name
UBoo.exe
EntryPoint
System.Void testeMatematico.Program::Main()
Scope Name
UBoo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
UBoo
Assembly Version
2.2.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
104
Main Method
System.Void testeMatematico.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void testeMatematico.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
testeMatematico.Form1.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
CHT
[NBF]root.Data
timer1.TrayLocation
testeMatematico.Properties.Resources.resources
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
ftcl
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙