Suspicious
Suspect

PE Executable
MD5: af26c57bb788fdab33813f656b634452
Size: 1.1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 af26c57bb788fdab33813f656b634452
Sha1 146f04baa63fc96c4280aa6de02384f6d8cf5eba
Sha256 823e02bde8acad7fd8fb24bd0f5628fcf9faacbe61efed1d47dd115ec63b55f9
Sha384 facd6504769ae64754f15a0a1714c0ff0aba0cd46c133de71bc61df9299e91c5ed52491e867478c73d1f961d6755cd22
Sha512 e0169416489021b00a088e4f0d4f3425ba9a179f6c5d064f686fc96f11e71da3013db97680fcb8fc6c0301b573b98686196054aeb9aea00ff0f9c8a4f7a98fbe
SSDeep 24576:u11ddpQ/l8GJLjDE2o4/OqRcxQNTGh65GyaozZ2wyJ:uBQ/XE2pOq76hryao92wy
TLSH 373512A431958A12D5BA47F919B2E33007F92D9FA851D303CEEEDCEB3811B5619493B3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterReminder.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
WaterReminder.Form1.resources
WaterReminder.Properties.Resources.resources
GT8
[NBF]root.Data
emNrjJH
[NBF]root.Data
[NBF]root.Data-preview.png
images
[NBF]root.Data
[NBF]root.Data-preview.png
images__1_
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
KoreanCalen
Full Name
KoreanCalen
EntryPoint
System.Void MethodReturnMessageWrap.RuntimeFeat::Main()
Scope Name
KoreanCalen
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oYRnfFO
Assembly Version
2.0.3.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
322
Main Method
System.Void MethodReturnMessageWrap.RuntimeFeat::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PolicyStatem.StreamingContextSta::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
KoreanCalen
Full Name
KoreanCalen
EntryPoint
System.Void MethodReturnMessageWrap.RuntimeFeat::Main()
Scope Name
KoreanCalen
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oYRnfFO
Assembly Version
2.0.3.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
322
Main Method
System.Void MethodReturnMessageWrap.RuntimeFeat::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PolicyStatem.StreamingContextSta::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterReminder.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
WaterReminder.Form1.resources
WaterReminder.Properties.Resources.resources
GT8
[NBF]root.Data
emNrjJH
[NBF]root.Data
[NBF]root.Data-preview.png
images
[NBF]root.Data
[NBF]root.Data-preview.png
images__1_
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙