Suspicious
Suspect

8e4c07963077228de130111ade5705e4

PE Executable
MD5: 8e4c07963077228de130111ade5705e4
Size: 1.04 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 8e4c07963077228de130111ade5705e4
Sha1 d257ff6bac266a0319f21630daca08440f8c911d
Sha256 d3d2e7c99c692c73840dc1cbb73b1613f4a4267104d6ce073df8c12d0c7e158a
Sha384 ab7999991060ad4b35ed35d162cad8e54417f2450dcea25510117137d73f24c973b31dd278912fbb7b99d71c03be56eb
Sha512 7df1fb71670d06c3e3feadf838aa96b377842b45c620a963a6b9b5c9b4b3f65c62e01380583c5a5801d6f757b54fc9eea17d6dcfd278ef1801c07baf507da0c4
SSDeep 24576:nsWguQrHxEm+TdUwH8i1U1hN/tLGXwCgpLo8hbVictUY:nsPuYHxGOKmj/tV/Qc
TLSH 52252265768CCC06D5AD07F16A70E33457B5AE9E6822D21AEFCFADF7B44A3420848353
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PixelRuler.Properties.Resources.resources
Clear
[NBF]root.Data
dSzHS
[NBF]root.Data
[NBF]root.Data-preview.png
werwre
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
MLangEnco
Full Name
MLangEnco
EntryPoint
System.Void CorrectionAlgori.EventComm::Main()
Scope Name
MLangEnco
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Gyxex
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
204
Main Method
System.Void CorrectionAlgori.EventComm::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SafeSerializationEventA.BIND::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
MLangEnco
Full Name
MLangEnco
EntryPoint
System.Void CorrectionAlgori.EventComm::Main()
Scope Name
MLangEnco
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Gyxex
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
204
Main Method
System.Void CorrectionAlgori.EventComm::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SafeSerializationEventA.BIND::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PixelRuler.Properties.Resources.resources
Clear
[NBF]root.Data
dSzHS
[NBF]root.Data
[NBF]root.Data-preview.png
werwre
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙