Suspicious
Suspect

PE Executable
MD5: a4829ee5d4fac80869382053f7f3ebe1
Size: 1.02 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 a4829ee5d4fac80869382053f7f3ebe1
Sha1 335c3d08f52bab55d05f463e2adad1fe8f96978b
Sha256 31ceaea6cb2e484b7ff1fdd6dcf0fdd999898548c5b5504e23561acbd1df53a0
Sha384 0dc250a324956d52b3d5c8da375a6e7d8e50d837c83e7f6aaee693629c4dc2104c524631993b1ea3236194b126c07fec
Sha512 4fb2594968fb140381bbe9510d10486d28224accb59e6150379017b85430454de11b43d91a6f588b9f68f517d6bf4f06d2971fd2c42085e4ced287adeb74c4c3
SSDeep 24576:UedY38bayeT8re1a+KmR9qEwgQ2t9dDBZJtCNPeUj2b:Uedm8bzeAreUMR95wgQsBxCmUj2b
TLSH 6E25F19C3614F8EEC887D5714EA0DEB4A2246D6AC717C1138AEB1DDFB91CD87DE041A2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
VKuV
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Czes.exe
Full Name
Czes.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
Czes.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Czes
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‌‏‪‬‌‏‮‪‍‮‌‎‪‌‪‭‍‏‌‬‌‍‬‪‪‍‭‮‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‌‍​‮‫‫‮‬‫‎‌‌‪‍‏‍‬‎‎‬‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::​‍‍‭‌‏​‭‏‬‭‎‎‏‌‮‮‍‪‭​‬​‎‏‎‬‏‌‮(System.Windows.Forms.Form)
ret <null>
Module Name
Czes.exe
Full Name
Czes.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
Czes.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Czes
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‌‏‪‬‌‏‮‪‍‮‌‎‪‌‪‭‍‏‌‬‌‍‬‪‪‍‭‮‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‌‍​‮‫‫‮‬‫‎‌‌‪‍‏‍‬‎‎‬‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::​‍‍‭‌‏​‭‏‬‭‎‎‏‌‮‮‍‪‭​‬​‎‏‎‬‏‌‮(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
VKuV
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙