Suspicious
Suspect

PE Executable
MD5: a28e5717a03df2743129f3fb516f3345
Size: 776.7 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 a28e5717a03df2743129f3fb516f3345
Sha1 eea59bdfe91c6a9fe39fc8cb0d7f7d06de1a534c
Sha256 aa7f31356193b7ed4e58e0ccc15635e3df06eaba6a81c0ff23bd68f17db18b87
Sha384 00755820c5b891d77ebeff19bac9bcb4f9ec54b6ada69c62e467a217b583b2f2a89288835dd2e141324a9acd45ed28b5
Sha512 6eceb88239689b0abf80b1693ed4b8e6908e2c344dcb8869e3ae6f508ad67825bb823950572926087aa774da1288c3f1a92e50b78c1791936162a491e4586d40
SSDeep 12288:Fh92tzFcft58pOIwatsmL15nJd+Kzgr/CEtnLZiJmuTQ9753HU9Ca:Fn2Lct58ITNmL15nJd+CkvnLZiJmuTQk
TLSH 19F401582B0EDF12D4A057F249A0E3B163747D8EF851E2126FE67DEBB42AF052918353
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BitTools.Forms.MainLauncher.resources
BitTools.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
vUZCIV
[NBF]root.Data
[NBF]root.Data-preview.png
xfi
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: CPobgB.pdb
Module Name
CPobgB.exe
Full Name
CPobgB.exe
EntryPoint
System.Void BitTools.Program::Main()
Scope Name
CPobgB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CPobgB
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
456
Main Method
System.Void BitTools.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BitTools.Forms.MainLauncher::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
CPobgB.exe
Full Name
CPobgB.exe
EntryPoint
System.Void BitTools.Program::Main()
Scope Name
CPobgB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CPobgB
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
456
Main Method
System.Void BitTools.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BitTools.Forms.MainLauncher::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BitTools.Forms.MainLauncher.resources
BitTools.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
vUZCIV
[NBF]root.Data
[NBF]root.Data-preview.png
xfi
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙