Suspicious
Suspect

PE Executable
MD5: 91ad1e56a658c1be71e223b6b2293732
Size: 882.18 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 91ad1e56a658c1be71e223b6b2293732
Sha1 0466a4eeb5daa494ba9bc6f0221d237a52c0af8c
Sha256 22d7ca89918de5ad403867dfc9b0fcae5f3f7c2b6f91cab12f1cc444fedd880b
Sha384 8095c527de285dac81f902151cb806a72308787200a2587599400dbe22ed52ec21f56cf8dfb854cf1e4009747924ca41
Sha512 37cbdbca9a507a40869d17d2c6d4d9be824514de84a35965a3b8d02c5d78534915e5ec6e29cdb6c74fa119a2b48eb70497cd4ca606b35d04e1e213123d9e9bd9
SSDeep 24576:c1Obk0M3QvI932snk6UM32aF0655hCHKJSa:cmk0MeEmsnk6UM32aF06bhC
TLSH 8715012C62C4DD66C76903766521E23DD6A88DA7A134C391FADE7DD73F39B0210632A3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CacPhepTinhTrenPhanSo.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
CacPhepTinhTrenPhanSo.Form1.resources
$this.Icon
[NBF]root.IconData
cgi
[NBF]root.Data
CacPhepTinhTrenPhanSo.Properties.Resources.resources
RERv
[NBF]root.Data
[NBF]root.Data-preview.png
BookStore.csdl
BookStore.msl
BookStore.ssdl
Name Value
Module Name
XfPd.exe
Full Name
XfPd.exe
EntryPoint
System.Void CacPhepTinhTrenPhanSo.Program::Main()
Scope Name
XfPd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XfPd
Assembly Version
2.8.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
142
Main Method
System.Void CacPhepTinhTrenPhanSo.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void CacPhepTinhTrenPhanSo.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CacPhepTinhTrenPhanSo.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
CacPhepTinhTrenPhanSo.Form1.resources
$this.Icon
[NBF]root.IconData
cgi
[NBF]root.Data
CacPhepTinhTrenPhanSo.Properties.Resources.resources
RERv
[NBF]root.Data
[NBF]root.Data-preview.png
BookStore.csdl
BookStore.msl
BookStore.ssdl
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙