Suspicious
Suspect

8953f538be3800b4dfe861cc3bb26ae5

PE Executable
MD5: 8953f538be3800b4dfe861cc3bb26ae5
Size: 1.22 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 8953f538be3800b4dfe861cc3bb26ae5
Sha1 24fc4d5bb2fa3f6b568493422a54d10249bfc970
Sha256 ecce093ae6875250d3f5ff7e82f1f595b2fa9cdcafac214dbbcef064b92f3ad4
Sha384 1281237016c647e15bab415a4fa7dd58a0c9f525ae6c7613bdb558032afdd28e95181167e846fd4e1586e2669609e1c4
Sha512 b1056043058538973a9e14ee12865d93f3779e499f4292494903c67c11d536511467b244ca28adb8865174497d135cea754524466fc7e10f47d5f1253bec0854
SSDeep 24576:JUfY9OJYddxZAk6M7Y2+j8WctxSRWnYrN9giT2Wbl0pqdD:JUHcdfKAJxtxS8Yki6WQ
TLSH B24522182399FE03E4B61FF41970E37813748D94A926E303DBEB6DDF74267413A4A296
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GradientCreator.Forms.MainForm.resources
GradientCreator.Properties.Resources.resources
Teacher
[NBF]root.Data
oSLs
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: aNST.pdb
Module Name
aNST.exe
Full Name
aNST.exe
EntryPoint
System.Void GradientCreator.Program::Main()
Scope Name
aNST.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
aNST
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
128
Main Method
System.Void GradientCreator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GradientCreator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
aNST.exe
Full Name
aNST.exe
EntryPoint
System.Void GradientCreator.Program::Main()
Scope Name
aNST.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
aNST
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
128
Main Method
System.Void GradientCreator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GradientCreator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GradientCreator.Forms.MainForm.resources
GradientCreator.Properties.Resources.resources
Teacher
[NBF]root.Data
oSLs
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙