Suspicious
Suspect

PE Executable
MD5: 8e52b511602c4a9ce5f42851dae96af2
Size: 1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 8e52b511602c4a9ce5f42851dae96af2
Sha1 b2c30aea26c8d309545a61c836e89fb0733e52ca
Sha256 b037ec84d28e701f78fb02c5e36064b921adddefca5e24587fb918c0fa9e294f
Sha384 800748499f2b8a69ff2ee9205a4143da56981b28efb33a93b074181b035916755bf023693bc8781812fcf9107fc7cd36
Sha512 58ffdd47ca7c66aa1431af1b9b42e0e56350f580997521e63d675f3d7c9dae2096f62ce33c290bdce9b68b4fdb6b54979598809224d429545ccde77b1449f060
SSDeep 24576:xRYkB67JiUJocdrQZBNqZC84R5zLAcGn:xq1iUJxy/784R5zs5
TLSH 9B2523B46808CE03DE2753BDA976F3FA01B8AE9D9155C3264BFE5DBB3879924102C1D1
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AdvancedColorPicker.AboutB.resources
$this.Icon
[NBF]root.IconData
AdvancedColorPicker.MainForm.resources
RGB
[NBF]root.Data
AdvancedColorPicker.Properties.Resources.resources
uEAH
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\gGFskYXFUv\src\obj\Debug\RAhT.pdb
Module Name
RAhT.exe
Full Name
RAhT.exe
EntryPoint
System.Void AdvancedColorPicker.Program::Main()
Scope Name
RAhT.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RAhT
Assembly Version
6.4.3.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
46
Main Method
System.Void AdvancedColorPicker.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AdvancedColorPicker.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
RAhT.exe
Full Name
RAhT.exe
EntryPoint
System.Void AdvancedColorPicker.Program::Main()
Scope Name
RAhT.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RAhT
Assembly Version
6.4.3.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
46
Main Method
System.Void AdvancedColorPicker.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AdvancedColorPicker.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AdvancedColorPicker.AboutB.resources
$this.Icon
[NBF]root.IconData
AdvancedColorPicker.MainForm.resources
RGB
[NBF]root.Data
AdvancedColorPicker.Properties.Resources.resources
uEAH
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙