Suspicious
Suspect

PE Executable
MD5: 978d25bdefd072f696331025851c7edb
Size: 778.24 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 978d25bdefd072f696331025851c7edb
Sha1 140d68073c11cf8ec78e2468f1300665691d4830
Sha256 93e14efc8eadf9f9dd7d4aae3b8d680e22ad771d94caa155cd2ee774b3712a3a
Sha384 f613e42b89d03c70ba2d4006fd869ffcacf6c8f34bab7ff68380115c07cf33e3e2f4d630b9a94fadb621ee232df191ba
Sha512 0436d3f65c6e55664b2cd1bb33fba18da87a1889193aa3762b30360681b25e549c3cd2c944a9c590decb979cd0d25fc58f6c2a1255a6db8cc2142367baf08fcf
SSDeep 12288:0qbo7VMtHPb31SRwWAmMjME6Nz9YUGhNoohWjTVdir7MmgGE/ZVEOa1/nkJs:Fbo7utHD3swJatz3GhNDrbgLmFkJs
TLSH B2F41288765BDF61CAA60BF50621D23213FBBDDDA821D3074FEAECE7B8207582544583
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
kIEo.exe
Full Name
kIEo.exe
EntryPoint
System.Void ModernAdapter.Program::Main()
Scope Name
kIEo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kIEo
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
617
Main Method
System.Void ModernAdapter.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void ModernAdapter.Program::InitializeApplication()
nop <null>
newobj System.Void ModernAdapter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
kIEo.exe
Full Name
kIEo.exe
EntryPoint
System.Void ModernAdapter.Program::Main()
Scope Name
kIEo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kIEo
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
617
Main Method
System.Void ModernAdapter.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void ModernAdapter.Program::InitializeApplication()
nop <null>
newobj System.Void ModernAdapter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
978d25bdefd072f696331025851c7edb
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
978d25bdefd072f696331025851c7edb
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙