Suspicious
Suspect

8f840f16c6427722b573e415552274c3

PE Executable
MD5: 8f840f16c6427722b573e415552274c3
Size: 488.45 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 8f840f16c6427722b573e415552274c3
Sha1 9f8fc81a0a7bfa9de0ee164bd200e2586363db7b
Sha256 e6f5ae1fff95e6ded8cd7181035cbf2ae06010bf21377b0830ec363b71b59af7
Sha384 5c26076b669c7c372d2917c172455de77cf2ffe19da3090ea065499405247851dbd2a320e8cd71f97bc82a2a5f01c0b3
Sha512 f4322867c37300e95067c42ad51cf836c2efa927f4037c1cdbb888d16e91eda8ac64abfa15e3cd095f06bbf4110163b1bdbcc6b263fb1ee676d2a7688feae303
SSDeep 12288:bOCF77zV2eqBQ051YhCIYaieMdncPN2/GNctKiQpzQ/8iOC:bHF7XV2vBI7ieMz/GOtKDiH
TLSH B0A4F1286F4ECD12D1C51AB009B2E3B47571DE8CE911D2135FFEBDEBB869956382C290
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
thinkgear_form.ProgramForm.resources
$this.Icon
[NBF]root.IconData
owu
[NBF]root.Data
thinkgear_form.Properties.Resources.resources
yvq
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\keQvGqKnKq\src\obj\x86\Debug\rNP.pdb
Module Name
rNP.exe
Full Name
rNP.exe
EntryPoint
System.Void thinkgear_form.Program::Main()
Scope Name
rNP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rNP
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
61
Main Method
System.Void thinkgear_form.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void thinkgear_form.ProgramForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
rNP.exe
Full Name
rNP.exe
EntryPoint
System.Void thinkgear_form.Program::Main()
Scope Name
rNP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rNP
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
61
Main Method
System.Void thinkgear_form.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void thinkgear_form.ProgramForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
thinkgear_form.ProgramForm.resources
$this.Icon
[NBF]root.IconData
owu
[NBF]root.Data
thinkgear_form.Properties.Resources.resources
yvq
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙