Suspicious
Suspect

af8df52ae52156ae23e137a90cc43f9f

PE Executable
MD5: af8df52ae52156ae23e137a90cc43f9f
Size: 754.69 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 af8df52ae52156ae23e137a90cc43f9f
Sha1 1e9ad45cd085ee56706ca14b5b6c11b34074e63e
Sha256 ef8d05170d65e8bc74f0a75d31a5fdb8f9c86abf388bf2d896e77acf8a0ff8f9
Sha384 4b9c1be0060cc7234222a1543f3f6c1428350e1455a3b93acbc64fadbb9e6b65c48c3a14de5709422d5c17236b1ae55f
Sha512 8b5483b51a0b3c88c36c553f06d9cfadbb547cf1c6cde226cfd7b077a7d043bb9662eb38d7964845438299fb4b59c3e930300babfcd206c2454c362b892d94d9
SSDeep 12288:07FnrlIVVcG0BIvyduFqTAA97Peq7nqCNojxvsHEfszkvwj9:07VrqXgBgygQ/97mq7VNo+HwZo
TLSH 63F40140F289FD0FC19A87B4C970D1B01EBA9EDAE101F58B9DE17E8F7876B700565286
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Magic8Ball2._0.Form1.resources
$this.Icon
[NBF]root.IconData
ball1
[NBF]root.Data
menuStrip1.TrayLocation
AsnanyDentalClinic.BufferingPage.resources
AsnanyDentalClinic.MyForms.RegisterationForm.resources
AsnanyDentalClinic.MyForms.SigninPage.resources
AsnanyDentalClinic.Properties.Resources.resources
IcOJ
[NBF]root.Data
[NBF]root.Data-preview.png
clickAnother2
[NBF]root.Data
[NBF]root.Data-preview.png
clickSubmit2
[NBF]root.Data
[NBF]root.Data-preview.png
close
[NBF]root.Data
[NBF]root.Data-preview.png
close2
[NBF]root.Data
[NBF]root.Data-preview.png
dentist
[NBF]root.Data
[NBF]root.Data-preview.png
magicballDROP4
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\vJvtRcSqZz\src\obj\Debug\vOBJ.pdb
Module Name
vOBJ.exe
Full Name
vOBJ.exe
EntryPoint
System.Void AsnanyDentalClinic.Program::Main()
Scope Name
vOBJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vOBJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
298
Main Method
System.Void AsnanyDentalClinic.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void AsnanyDentalClinic.BufferingPage::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
vOBJ.exe
Full Name
vOBJ.exe
EntryPoint
System.Void AsnanyDentalClinic.Program::Main()
Scope Name
vOBJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vOBJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
298
Main Method
System.Void AsnanyDentalClinic.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void AsnanyDentalClinic.BufferingPage::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Magic8Ball2._0.Form1.resources
$this.Icon
[NBF]root.IconData
ball1
[NBF]root.Data
menuStrip1.TrayLocation
AsnanyDentalClinic.BufferingPage.resources
AsnanyDentalClinic.MyForms.RegisterationForm.resources
AsnanyDentalClinic.MyForms.SigninPage.resources
AsnanyDentalClinic.Properties.Resources.resources
IcOJ
[NBF]root.Data
[NBF]root.Data-preview.png
clickAnother2
[NBF]root.Data
[NBF]root.Data-preview.png
clickSubmit2
[NBF]root.Data
[NBF]root.Data-preview.png
close
[NBF]root.Data
[NBF]root.Data-preview.png
close2
[NBF]root.Data
[NBF]root.Data-preview.png
dentist
[NBF]root.Data
[NBF]root.Data-preview.png
magicballDROP4
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙