Suspicious
Suspect

PE Executable
MD5: 9b52d8498324a615edb04157f0cbe8be
Size: 592.9 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 9b52d8498324a615edb04157f0cbe8be
Sha1 92a1bb188aaffc7bf2992f3f4c869328c9813703
Sha256 2ed366c595c98fbfe00e692f6d7e06dd237bc2fce08070b610e220083bdb1fe4
Sha384 bd18e44acc525aa9886c21180be45ac0ab09e5ec570dc5abe283e618e48f68ec1cd2929fd2f07d2a60debf6f99c441b3
Sha512 90df52877cd609edafbc8c83e608629fd2a94a4f89f365159201e5405f1ae0a4f8fb3065ae97898c6925b34a9e1c9be65a1be2134740ebcaf287fc0bc4589c7f
SSDeep 12288:fj7MBeO8XtYFKleO+COqXrlRZWpmmebGPr1llfnQ0qbdvnJ5Z:fj7MonPTiqXrlrWpzPPr1bVqbFZ
TLSH 2DC401683212D813CA65A3B40571F27812BD8EE9F511E782BFD97E9F78BAF110C14693
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
EstudoTaskool.frmCadastro.resources
$this.Icon
[NBF]root.IconData
EstudoTaskool.Views.frmListaUsuario.resources
EstudoTaskool.Properties.Resources.resources
GTDu
[NBF]root.Data
[NBF]root.Data-preview.png
foto
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
Database.DBModel.csdl
Database.DBModel.msl
Database.DBModel.ssdl
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
ECVd.exe
Full Name
ECVd.exe
EntryPoint
System.Void EstudoTaskool.Program::Main()
Scope Name
ECVd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ECVd
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
144
Main Method
System.Void EstudoTaskool.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void EstudoTaskool.FrmPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
ECVd.exe
Full Name
ECVd.exe
EntryPoint
System.Void EstudoTaskool.Program::Main()
Scope Name
ECVd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ECVd
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
144
Main Method
System.Void EstudoTaskool.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void EstudoTaskool.FrmPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
EstudoTaskool.frmCadastro.resources
$this.Icon
[NBF]root.IconData
EstudoTaskool.Views.frmListaUsuario.resources
EstudoTaskool.Properties.Resources.resources
GTDu
[NBF]root.Data
[NBF]root.Data-preview.png
foto
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
Database.DBModel.csdl
Database.DBModel.msl
Database.DBModel.ssdl
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙