Suspicious
Suspect

PE Executable
MD5: 924fe8886f23c9058feb8aaecd0e7fcb
Size: 966.14 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 924fe8886f23c9058feb8aaecd0e7fcb
Sha1 73a8682d307691610b3229bd83301c08406d17f6
Sha256 4e334ecb7d9d523704490dfa106cd65cd0779436afed6b22f701f7f16f5d35f5
Sha384 b5749369a63cfaf247de083f78afe5d7d33c14bcb7e35baa201b7b46f3e66c0002abf8a326b587e87fd54f9d8a80bab2
Sha512 a72b4367b2974ceb7d7c86af487965503efbbbebd9780938ac6defb305ff20a1031705d07cfd59e81573df3b64a302ead8086e18684225c60b2caf0e6d6ee984
SSDeep 24576:DMaaS/XLbQH/EQPcRbRWePFTtu2WmZ7ajb:HB/bbQnPpAtvW9
TLSH 352512053A7D9C03DA7E57F00A72C17443B99CCEA562E3C6AEC92DDB34E27214A42B57
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StreamlinedHelper.MainForm.resources
StreamlinedHelper.Properties.Resources.resources
WebD
xsh
Name Value
Module Name
eZsz.exe
Full Name
eZsz.exe
EntryPoint
System.Void StreamlinedHelper.Program::Main()
Scope Name
eZsz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
eZsz
Assembly Version
7.0.0.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
560
Main Method
System.Void StreamlinedHelper.Program::Main()
Main IL Instruction Count
7
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void StreamlinedHelper.Program::InitializeApplication()
newobj System.Void StreamlinedHelper.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
eZsz.exe
Full Name
eZsz.exe
EntryPoint
System.Void StreamlinedHelper.Program::Main()
Scope Name
eZsz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
eZsz
Assembly Version
7.0.0.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
560
Main Method
System.Void StreamlinedHelper.Program::Main()
Main IL Instruction Count
7
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void StreamlinedHelper.Program::InitializeApplication()
newobj System.Void StreamlinedHelper.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
PDB Path PATH
eZhuhuhuhu
Embedded Resources UNKNWOWNsuspect
9huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StreamlinedHelper.MainForm.resources
StreamlinedHelper.Properties.Resources.resources
WebD
xsh
No malware configuration was found at this point.
PDB Path PATH
eZhuhuhuhu
924fe8886f23c9058feb8aaecd0e7fcb
Embedded Resources UNKNWOWNsuspect
9huhuhuhu
924fe8886f23c9058feb8aaecd0e7fcb
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
924fe8886f23c9058feb8aaecd0e7fcb
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙