Suspicious
Suspect

PE Executable
MD5: a566eee26635e15c9a70ef7765113751
Size: 836.1 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 a566eee26635e15c9a70ef7765113751
Sha1 332c9f509790f55898b526b5244bbc1186552bca
Sha256 8cfd63cd0b610d3bd1e5712b0f7019aa22b97ccc98df8ce65f047c5a91bbeaa7
Sha384 b917246f19b85606604e8b1c9eee68e9bb8825fe7b0ca87121371e8706b14e000ac439729aa46e3b06f518ee6ae77f1e
Sha512 eacea7a62e863b9922a69d853538ccf852e31319eba347f782c7f2512516a5bf86073c252cb6786b8b176fe1db02da6ae3a997c22194b705772e25f4b67b5078
SSDeep 24576:cMM6WD3lrZcWzJEagf0qyFc8VjyXKvQN/:czD3lruWtEaNVQgQF
TLSH 9205122636B5CB20D4FD43F54A33E23603B16C6EA531E3068FE26DE73125B919A15B93
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ScientificCalculator.Forms.GraphPlotterForm.resources
Scientific_Calc.Properties.Resources.resources
JfHu
[NBF]root.Data
[NBF]root.Data-preview.png
PIP
[NBF]root.Data
t1
[NBF]root.Data
[NBF]root.Data-preview.png
t2
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
oUTq.exe
Full Name
oUTq.exe
EntryPoint
System.Void ScientificCalculator.Program::Main()
Scope Name
oUTq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oUTq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
380
Main Method
System.Void ScientificCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ScientificCalculator.Forms.MainCalculatorForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
oUTq.exe
Full Name
oUTq.exe
EntryPoint
System.Void ScientificCalculator.Program::Main()
Scope Name
oUTq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oUTq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
380
Main Method
System.Void ScientificCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ScientificCalculator.Forms.MainCalculatorForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
oUhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ScientificCalculator.Forms.GraphPlotterForm.resources
Scientific_Calc.Properties.Resources.resources
JfHu
[NBF]root.Data
[NBF]root.Data-preview.png
PIP
[NBF]root.Data
t1
[NBF]root.Data
[NBF]root.Data-preview.png
t2
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
oUhuhuhuhu
a566eee26635e15c9a70ef7765113751
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙