Suspicious
Suspect

PE Executable
MD5: 8c5dbc16c494e0c522811656e3e871ca
Size: 578.56 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 8c5dbc16c494e0c522811656e3e871ca
Sha1 df5fa23be0e52bc5accbc04bd4612622c339839c
Sha256 7215cbe8e5dfed7b22c8bbe8c5f7f35a7848e545d1cdeb60a378baf0be32cb0e
Sha384 66c7cbda96ef23fcf06aa3f14a16317e18500371245bd4cf87a6b99c3017061ab81be3ebc1278563ebbcffffc843382a
Sha512 067b24fdf386eab2be2380c9d95ab9c4985b870b4b13de11037452cba8860f5f31377ec5e350c0b695964b9b41abf15422b2f6e5c0a4dcc019eb6217b0ca93a7
SSDeep 12288:dedYZELpR73pGRFJY+qYEZ7/Wn1cq0xtJqJZVa6M/Z6VU4Sc:dedYSLr30RFJZhau1cRq
TLSH BFC4DF9C3615F9AFC887C57189A4EE74A6202D6AD30AC11385E71CDFB50DE97EE081E3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
UwRe
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
zIpD.exe
Full Name
zIpD.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
zIpD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zIpD
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‬‬‎‮‮‮‎‎‍‪‍‎‏‫‬‏‭​‭‌‌‏‭‭‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‏‬‮‌‫‏‎‮‌‮‎‌‎‮‮‌‫‫​‏‌‭‫‬‎‪‫‭‌‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::‮‮‏‬​‎‭‍​​‌‍‬‪‮‎‫‭​‪‪‮‮‭‏‮(System.Windows.Forms.Form)
ret <null>
Module Name
zIpD.exe
Full Name
zIpD.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
zIpD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zIpD
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‬‬‎‮‮‮‎‎‍‪‍‎‏‫‬‏‭​‭‌‌‏‭‭‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‏‬‮‌‫‏‎‮‌‮‎‌‎‮‮‌‫‫​‏‌‭‫‬‎‪‫‭‌‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::‮‮‏‬​‎‭‍​​‌‍‬‪‮‎‫‭​‪‪‮‮‭‏‮(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
UwRe
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙