Suspicious
Suspect

PE Executable
MD5: 9138f52414b51ce0a6363b6b6b535bac
Size: 763.9 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 9138f52414b51ce0a6363b6b6b535bac
Sha1 c12626de864323cd4ceb58a0c96b58144272af8a
Sha256 4620e415f8bcd713bdfbcba4e710e79c2e057d2e15dbbe2c3a39e8a229563038
Sha384 2e68fe8278da616f68257a0f7f0a6494479d1b773c866aaad25558572c0cd999f14d485dc842cf7d09ea00f765f18b56
Sha512 a3be255e904d20fe3c8c509be917d87822ffd9d54bfb51fa0b8aa1a11d0c9ececa2b07b1aa73f069bf050270b52e50b9ebcfe6b84b7df583033ea6672beea840
SSDeep 12288:rQAHVBffWZuKsfUOsCbcfPNqqSkT8JeMkMiZMfKkoo6dMPTy4Umtu:EeBffMsB2JTvccMfKkoo6dOy4Umtu
TLSH B5F401136749C912CBF743B04D63D7B552684EEA9811C3D78AE9BFE338362469C80DA7
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BTH1.Calculator1.resources
$this.Icon
[NBF]root.IconData
BTH1.Calculator2.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
FT
[NBF]root.Data
BTH1.Properties.Resources.resources
ObP
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: lbT.pdb
Module Name
lbT.exe
Full Name
lbT.exe
EntryPoint
System.Void BTH1.Program::Main()
Scope Name
lbT.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lbT
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
98
Main Method
System.Void BTH1.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BTH1.Calculator2::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BTH1.Calculator1.resources
$this.Icon
[NBF]root.IconData
BTH1.Calculator2.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
FT
[NBF]root.Data
BTH1.Properties.Resources.resources
ObP
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙