Suspicious
Suspect

PE Executable
MD5: ad94776ed32999f23240fa1b67651f2e
Size: 837.12 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 ad94776ed32999f23240fa1b67651f2e
Sha1 6a1e7076f6a4de2d04336ae0f9c82f4467876c74
Sha256 90ee1e7a6193aa7c62de6fd466fc0ca1fe7b8aaec67fa98e96183079222593f4
Sha384 bd3adeb32f064f2f46f700121d318b014cac3d845619e337029cea60b6b3cb307b0ed08a6e02c2dcca5497d3f09e49c2
Sha512 977b905afca4d9c113080add27e759d02d4bbde56431c65e741bab9494ec485b70768fccd9d0f05b9b689123b01fc218cc37ca53313cc4312e1ea950b7c3396a
SSDeep 12288:DVojyGJPztq0rlsg1hIHRtK1YhNAhp2PPV5JiDStH/NpYo4HQTqm:61rlsg1SHvKINAhEnV5oStH/jYSq
TLSH 4705E0D03A76771ACEA54A71A569EDB582F41D687011BEF719DC3B8B34AC600AE0CF42
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorCodes.Form1.resources
ColorCodes.Properties.Resources.resources
SmallCatttt
[NBF]root.Data
[NBF]root.Data-preview.png
V6
[NBF]root.Data
klFl
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: VOEC.pdb
Module Name
VOEC.exe
Full Name
VOEC.exe
EntryPoint
System.Void ColorCodes.Program::Main()
Scope Name
VOEC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VOEC
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
213
Main Method
System.Void ColorCodes.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ColorCodes.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
VOEC.exe
Full Name
VOEC.exe
EntryPoint
System.Void ColorCodes.Program::Main()
Scope Name
VOEC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VOEC
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
213
Main Method
System.Void ColorCodes.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ColorCodes.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorCodes.Form1.resources
ColorCodes.Properties.Resources.resources
SmallCatttt
[NBF]root.Data
[NBF]root.Data-preview.png
V6
[NBF]root.Data
klFl
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙