Suspicious
Suspect

Spreadsheet.exe

PE Executable
MD5: a249a2280a9bc5af6263ad3cc77a22d4
Size: 809.98 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 a249a2280a9bc5af6263ad3cc77a22d4
Sha1 4e3d499def302685179f52c4a8f4fd434361ae8a
Sha256 fb950059d4dbf088a3f81339ba49bb503db94d915f1dc5707eaed1bffe7ba263
Sha384 38a5661b39d873d767986e347fd1b4291a8a58c8ebce14a571e8783b4e0886080fd87bef1526cf0b140be9f92045b8b7
Sha512 043f84c4e52a55ce781819f7b90aa2cb0906450d9cc92031a6a5ee1e030e3356c856aba8f50a9e77adcbfbc83d7d0150b0bd376b8f808762255054768d918af6
SSDeep 24576:QqC5abyBNPyr/pumXHAuHtQNluwLVuVgdHfmnf2:fbvr/pJAuNmQSVuGmf
TLSH 3505DF9C3251B59FC493C9318DA4ED70AA247DAA930BD20390D71DABBD0E99BDF141F2
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CSVViewer.Forms.MainForm.resources
CSVViewer.Properties.Resources.resources
KS
[NBF]root.Data
SRxB
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ucTW.exe
Full Name
ucTW.exe
EntryPoint
System.Void CSVViewer.Program::Main()
Scope Name
ucTW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ucTW
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
183
Main Method
System.Void CSVViewer.Program::Main()
Main IL Instruction Count
43
Main IL
nop <null>
ldc.i4 -1245001980
ldc.i4 -623188456
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.6 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0083: ret
nop <null>
ldloc.0 <null>
ldc.i4 -231718416
mul <null>
ldc.i4 2108801866
xor <null>
br.s IL_0006: ldc.i4 -623188456
nop <null>
ldc.i4.0 <null>
call System.Void CSVViewer.Program::‎‭‮‪‎​‌‪​‪​‭‎‪​‏​‫‪‪‬‎‪‮‏‏‪‎‮(System.Boolean)
ldloc.0 <null>
ldc.i4 55895918
mul <null>
ldc.i4 1616117381
xor <null>
br.s IL_0006: ldc.i4 -623188456
nop <null>
newobj System.Void CSVViewer.Forms.MainForm::.ctor()
call System.Void CSVViewer.Program::‎​‍‪‏​‮‏‪‭‭‭‬​‬‮​‬‫‍‍​‏‎‍‬‌‌‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 1104787523
mul <null>
ldc.i4 1771559466
xor <null>
br.s IL_0006: ldc.i4 -623188456
call System.Void CSVViewer.Program::‫‫​‪‎‌‫‍​‬‮​‪​‬‭‌‪‎‏‮‬‮‫‮()
ldloc.0 <null>
ldc.i4 -1704156889
mul <null>
ldc.i4 1329810689
xor <null>
br.s IL_0006: ldc.i4 -623188456
ret <null>
Module Name
ucTW.exe
Full Name
ucTW.exe
EntryPoint
System.Void CSVViewer.Program::Main()
Scope Name
ucTW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ucTW
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
183
Main Method
System.Void CSVViewer.Program::Main()
Main IL Instruction Count
43
Main IL
nop <null>
ldc.i4 -1245001980
ldc.i4 -623188456
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.6 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0083: ret
nop <null>
ldloc.0 <null>
ldc.i4 -231718416
mul <null>
ldc.i4 2108801866
xor <null>
br.s IL_0006: ldc.i4 -623188456
nop <null>
ldc.i4.0 <null>
call System.Void CSVViewer.Program::‎‭‮‪‎​‌‪​‪​‭‎‪​‏​‫‪‪‬‎‪‮‏‏‪‎‮(System.Boolean)
ldloc.0 <null>
ldc.i4 55895918
mul <null>
ldc.i4 1616117381
xor <null>
br.s IL_0006: ldc.i4 -623188456
nop <null>
newobj System.Void CSVViewer.Forms.MainForm::.ctor()
call System.Void CSVViewer.Program::‎​‍‪‏​‮‏‪‭‭‭‬​‬‮​‬‫‍‍​‏‎‍‬‌‌‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 1104787523
mul <null>
ldc.i4 1771559466
xor <null>
br.s IL_0006: ldc.i4 -623188456
call System.Void CSVViewer.Program::‫‫​‪‎‌‫‍​‬‮​‪​‬‭‌‪‎‏‮‬‮‫‮()
ldloc.0 <null>
ldc.i4 -1704156889
mul <null>
ldc.i4 1329810689
xor <null>
br.s IL_0006: ldc.i4 -623188456
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CSVViewer.Forms.MainForm.resources
CSVViewer.Properties.Resources.resources
KS
[NBF]root.Data
SRxB
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙