Suspicious
Suspect

PE Executable
MD5: a0ee5b10fdabfcd16d33978a1afcc0b1
Size: 864.77 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 a0ee5b10fdabfcd16d33978a1afcc0b1
Sha1 0655c2c4b0af6b2fbb10f95ec60fa21fb521d399
Sha256 20904547a31f2d227b7340bdbe384902d173dcfdf3a45797eef36a5cf0d0518d
Sha384 fb34c48f361e6aa08326cdc2a91cc6c86f962b0ee3ae9020bd13f51e571f67a2214e05bc9e5207d7a4bd2e5c60da11ed
Sha512 45ae54d9baa439deeb09ce4e9bb624461bc6d567f80042a621d14c8f87147b7a06b607b0cc8bf3a8460662a85f8db5b8bd2b7d3c8fb72f258297b569a957718d
SSDeep 12288:uXNQZ5NIcM7wTNAfowqdz9gt0z7nE9NpKs/u71x9VzhNjY0UL0RqdfAZPlyWhEAp:EN0+MBAqV9gCSpt+ZhRjUcqK4QEAE
TLSH F3051254375AE602E2F24FB41831D7B003B8BC0EAD21D24A9EFAECEF78797505861756
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HTMLValidator.Forms.MainForm.resources
HTMLValidator.Properties.Resources.resources
Fafy
[NBF]root.Data
[NBF]root.Data-preview.png
dr
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: uXwB.pdb
Module Name
uXwB.exe
Full Name
uXwB.exe
EntryPoint
System.Void HTMLValidator.Program::Main()
Scope Name
uXwB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
uXwB
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
364
Main Method
System.Void HTMLValidator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HTMLValidator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
uXwB.exe
Full Name
uXwB.exe
EntryPoint
System.Void HTMLValidator.Program::Main()
Scope Name
uXwB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
uXwB
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
364
Main Method
System.Void HTMLValidator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HTMLValidator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HTMLValidator.Forms.MainForm.resources
HTMLValidator.Properties.Resources.resources
Fafy
[NBF]root.Data
[NBF]root.Data-preview.png
dr
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙