Suspicious
Suspect

PE Executable
MD5: a81aa8a98fd78ab03964052379c6b987
Size: 742.4 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 a81aa8a98fd78ab03964052379c6b987
Sha1 681bd0881afa6475e14dc47c4ae1b69b8fe3956a
Sha256 68b9da7d7c581d929c84aca89b0d7418c6b2e04a6c93d1045e59052a7bedb6fd
Sha384 79c29394354baebb4befeb01b5a73a6f65951b269d93ca6975fda30b874cfde579f1176461048835c137461bc1a04883
Sha512 a9bed4d6463a46a522bd319430cfd0864a7df5626f4907d923b7cbad3eaccacfe1fcc9b39f01f9bddd92a477a9418c541adc1b788c7f3c54a5cebe5b10a065b6
SSDeep 12288:u4kuFKG62Vmm9mXKh3lWd+BowuzeW/TV8biiItnng2tpA5mGgkOaEpN3Rhan2u9:uAkah3lWd8V5i5nnrpAnfCR
TLSH 65F4F1893610F15FC453DA3189A5EE759A692DAA5707C20396E72DEFBC0C6D78E002F2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WorldClock.Form1.resources
WorldClock.Properties.Resources.resources
sfpR
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
YFst.exe
Full Name
YFst.exe
EntryPoint
System.Void WorldClock.Program::Main()
Scope Name
YFst.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YFst
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
165
Main Method
System.Void WorldClock.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void WorldClock.Program::‪​‌‭‭‌‎​‭‫‮‎‌‭‎‏‎‏‫‏​‭‮()
nop <null>
ldc.i4.0 <null>
call System.Void WorldClock.Program::​‬‎‌‫‏‫‎‍‌‍‏‪‎‌‪‎‫‎‫​‫‏‮‌​‏​‎‍‏‬‫‎‮(System.Boolean)
nop <null>
newobj System.Void WorldClock.Form1::.ctor()
call System.Void WorldClock.Program::‭‪‮‫​‎‎‬‫‮‭‌‏‎​‮‏‪‬‫​‬‌‏‭‮(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
YFst.exe
Full Name
YFst.exe
EntryPoint
System.Void WorldClock.Program::Main()
Scope Name
YFst.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YFst
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
165
Main Method
System.Void WorldClock.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void WorldClock.Program::‪​‌‭‭‌‎​‭‫‮‎‌‭‎‏‎‏‫‏​‭‮()
nop <null>
ldc.i4.0 <null>
call System.Void WorldClock.Program::​‬‎‌‫‏‫‎‍‌‍‏‪‎‌‪‎‫‎‫​‫‏‮‌​‏​‎‍‏‬‫‎‮(System.Boolean)
nop <null>
newobj System.Void WorldClock.Form1::.ctor()
call System.Void WorldClock.Program::‭‪‮‫​‎‎‬‫‮‭‌‏‎​‮‏‪‬‫​‬‌‏‭‮(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WorldClock.Form1.resources
WorldClock.Properties.Resources.resources
sfpR
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙