Suspicious
Suspect

PE Executable
MD5: 9cbd51dee7bffe326a2464b2d68317fd
Size: 102.98 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 9cbd51dee7bffe326a2464b2d68317fd
Sha1 1ef4e8f88e46932a338cb1209fb45ea8b5fefa3b
Sha256 5005f4dd86b2bf19ea984feec50b9fe489967af0311e851727912e20920ea414
Sha384 a6b302fc4fc0822b5a28ca09aad2cb3845e42a65a6fc7682ac3b3624fc325e7e87d08f211731c3f831096ce56b3e227e
Sha512 7975c254db7a19802a44aa0a7fb78a341986af6e7e8eab898e6c83ca9e1ab83486e4ba409494fcc6be0504757af6ecbc70dcaf6e4f8b2a0bca5cec98f51ed9f6
SSDeep 1536:WAp5eznKUlIOp3YjVCguHEvQEbFqVC3woFRKpT4Xk:d5eznsjsguGDFqGU
TLSH 1FA3DB387D952133C67EC1F689E90A8AEB69223F3191E9ED4CA742C418B2F156DC1D1F
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
26fc2.resources
1973c.png
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
1.exe
Full Name
1.exe
EntryPoint
System.Void MusicExpress.Program::Main()
Scope Name
1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
1
Assembly Version
1.28.14.52
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
1178
Main Method
System.Void MusicExpress.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void MusicExpress.MusicExpressMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
1.exe
Full Name
1.exe
EntryPoint
System.Void MusicExpress.Program::Main()
Scope Name
1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
1
Assembly Version
1.28.14.52
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
1178
Main Method
System.Void MusicExpress.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void MusicExpress.MusicExpressMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
26fc2.resources
1973c.png
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙