Suspicious
Suspect

a89b3ba1806cc0a4dc16d8120a12413c

PE Executable
MD5: a89b3ba1806cc0a4dc16d8120a12413c
Size: 714.75 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 a89b3ba1806cc0a4dc16d8120a12413c
Sha1 d34ec98c00831e7f2208e8e12dabd0cdf2f3d128
Sha256 b7da4b2bd1caa35f1940adbfa56ef8ff5fc6d7c4ebd49716a188fe480000e530
Sha384 3db8f63228f44a826663921b2d0d3bdf39c672041fb55db5134114ceaa5903e94b7ceb03ad80816f9a06584a85eaa887
Sha512 f07799ff88227fbe2144fb2e015ff68fa52ec78e84e18a54993f0f0283d99e873760070112bb5a8da51fdd6529b225abeeb1f28bb158dbea52b5662e62c2e7dc
SSDeep 12288:0uEB2iNgbpO0M39ydnyC4yhoKfd9PaWeyh8xMcyxFX81azQEw0wz:M1Obk0M3QdnyC4yhNryWey2xMZfw5
TLSH 24E4E16863C49D66C2A90376A521F3BDD6948DBBE134C391FBCE7D973F297012027262
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CacPhepTinhTrenPhanSo.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
CacPhepTinhTrenPhanSo.Form1.resources
$this.Icon
[NBF]root.IconData
cgi
[NBF]root.Data
CacPhepTinhTrenPhanSo.Properties.Resources.resources
RGVT
[NBF]root.Data
[NBF]root.Data-preview.png
BookStore.csdl
BookStore.msl
BookStore.ssdl
Name Value
Module Name
klUb.exe
Full Name
klUb.exe
EntryPoint
System.Void CacPhepTinhTrenPhanSo.Program::Main()
Scope Name
klUb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
klUb
Assembly Version
2.8.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
142
Main Method
System.Void CacPhepTinhTrenPhanSo.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void CacPhepTinhTrenPhanSo.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CacPhepTinhTrenPhanSo.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
CacPhepTinhTrenPhanSo.Form1.resources
$this.Icon
[NBF]root.IconData
cgi
[NBF]root.Data
CacPhepTinhTrenPhanSo.Properties.Resources.resources
RGVT
[NBF]root.Data
[NBF]root.Data-preview.png
BookStore.csdl
BookStore.msl
BookStore.ssdl
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙