Suspicious
Suspect

PE Executable
MD5: 973d445ef4c7b2d2c1e0288000b32bc0
Size: 1.28 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 973d445ef4c7b2d2c1e0288000b32bc0
Sha1 40108af1e1b3ffc13651d9db05dd293ef1d8b360
Sha256 8bb2dbabe7d51170b77fe6f9ac6a050fddb145be3015e791f7991cf0ed730654
Sha384 95de9174ad5faf55d9c34e3901688037d9278a06c9ad2eb6b1c9ea2d87fd0988807ce6175852927d7a2e4dcd762941cd
Sha512 c972299557b86852c3aa2f30139e903dfc72cea21a8990387df0790f49312da892d36a02aec1078056ae10e3cc85bba049522a3025246813779166947d9747ea
SSDeep 24576:E3HUcm3eN9H5KWyeyhkSafzbLEKsNnFm2rH6RMSpb/fzgOJX93J24a:E3tm3eEW1yTNdHSMSpPHb3J2D
TLSH 4155225427ABDE12C4A617B44930D37103396E4DE852E32B4EE9BCEFB876F052849393
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
conversorImagens.Form1.resources
$this.Icon
[NBF]root.IconData
openFileDialog1.TrayLocation
xfi
[NBF]root.Data
Personel_Kayit.FrmAnaForm.resources
Personel_Kayit.FrmGiris.resources
Personel_Kayit.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
avuVxV
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
reHekC.exe
Full Name
reHekC.exe
EntryPoint
System.Void Personel_Kayit.Program::Main()
Scope Name
reHekC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
reHekC
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
327
Main Method
System.Void Personel_Kayit.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Personel_Kayit.FrmGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
reHekC.exe
Full Name
reHekC.exe
EntryPoint
System.Void Personel_Kayit.Program::Main()
Scope Name
reHekC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
reHekC
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
327
Main Method
System.Void Personel_Kayit.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Personel_Kayit.FrmGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
conversorImagens.Form1.resources
$this.Icon
[NBF]root.IconData
openFileDialog1.TrayLocation
xfi
[NBF]root.Data
Personel_Kayit.FrmAnaForm.resources
Personel_Kayit.FrmGiris.resources
Personel_Kayit.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
avuVxV
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙