Suspicious
Suspect

PE Executable
MD5: a772523f77cdda17220f352ba25faa0f
Size: 620.54 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 a772523f77cdda17220f352ba25faa0f
Sha1 5e67415767d53ebade412b4f50e2ba4bf0eafe4a
Sha256 23992ab41872ac21dcd499a48a743e51afa43d873d8564a95f03f4a639d3bfbc
Sha384 a2ca36e9bfd3f96de9312460f8e390209ae75197c1f654056c6e7a4c9da092e7708e2d7f99617421d8b070b76c9a8672
Sha512 b1f84674773c262594d128623bbb16640639232a37781719fcd1f8b83054e4658ff9dc4bdb113bb547f747cf9278cc879739a994cd42d795edb45ad2a27e9dd0
SSDeep 12288:tnmqa//SzJ+3yCLjej5veHEboyiUL1QKH5IqncZ2Z4Wo:tmp//Sz6ymSFveHwoyiUG4VcZe4Wo
TLSH 75D41244376BCB06C5A297B969F2F170177D2EAEA820C30A4FD92EDF7966F044910793
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModularExponentiation.Forms.MainForm.resources
ModularExponentiation.Properties.Resources.resources
Moon
[NBF]root.Data
XXHh
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: fKCk.pdb
Module Name
fKCk.exe
Full Name
fKCk.exe
EntryPoint
System.Void ModularExponentiation.Program::Main()
Scope Name
fKCk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
fKCk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
224
Main Method
System.Void ModularExponentiation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ModularExponentiation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
fKCk.exe
Full Name
fKCk.exe
EntryPoint
System.Void ModularExponentiation.Program::Main()
Scope Name
fKCk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
fKCk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
224
Main Method
System.Void ModularExponentiation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ModularExponentiation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModularExponentiation.Forms.MainForm.resources
ModularExponentiation.Properties.Resources.resources
Moon
[NBF]root.Data
XXHh
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙