Suspicious
Suspect

PE Executable
MD5: 8c4d51fc42bcd0a008f97f0bd34a5fe9
Size: 769.02 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 8c4d51fc42bcd0a008f97f0bd34a5fe9
Sha1 c453b309f7a8aebb4a1a25b0f1a7bed027c21ffd
Sha256 b3c88415963de8d3885dfb1f8f6ac107ff8ee35881bcd0ec48c196fac52a2bad
Sha384 88326ad1e9a523df99f2004067c78af67a7dae78ee8e5f3418a83ced8b47ffd71ac8713e441e27532d0bfbb07ccda2e4
Sha512 d2ff5fa9b51474d94b9150210cd58c4ea35ce396d5270b6a11834b9711ce5b70a12544194a5f13acc02e9267d3d87cab1ed4bca29bb20f313ac387610ede4838
SSDeep 12288:tHf7ALRtlalDHAGiGKu1gbB1L3LMNBOL6WLAPrwu+juWsj2etii4zhP+:tHf7ERilDpLzgld3LM7YLAs0jcH9
TLSH D3F40248375EEF12D8A61BF50970D37113B49E59A821E3164FEABCEB70BAF542818743
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpaceCalculator.MainForm.resources
SpaceCalculator.Properties.Resources.resources
CHT
[NBF]root.Data
SEtQ
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: XpTb.pdb
Module Name
XpTb.exe
Full Name
XpTb.exe
EntryPoint
System.Void SpaceCalculator.Program::Main()
Scope Name
XpTb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XpTb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
414
Main Method
System.Void SpaceCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpaceCalculator.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpaceCalculator.MainForm.resources
SpaceCalculator.Properties.Resources.resources
CHT
[NBF]root.Data
SEtQ
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙