Suspicious
Suspect

PE Executable
MD5: b224dae94650d2c68036ee7a9f52dc8f
Size: 759.81 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b224dae94650d2c68036ee7a9f52dc8f
Sha1 d44dd88b2e6e1627882ea8c7d89ca3b089439a09
Sha256 a2baea783b7929235c15f8b354fdb7a4dc5a251c97a0c3973cedd4eaa6dccf2a
Sha384 b0c3aa7e379c3d945bc418cc1bcd14fa05544d27af46192eb3f5b7f1af508ae914b009356b473a712c47ee30da4261db
Sha512 a1044c7008b738fa4a927ab16b0b6d18c13dd7d98b2a264660d453fd30c59e3eed8444275e688c8999a57d4d47d7bda9b425f0f621b020989fc1e90b257df237
SSDeep 12288:7khEAEZoOCgtOgYwNWPw+qecoOqlCuTjNt5d264+lqkdfGdQANfaMveBH/w:7WEAEZoOCgZ3NWPw+qePlHBdznlJdQQF
TLSH 6DF4025523AAF902E1F25BB00CB0D6F417B8BE8DBC21D2065EE6EDEFB8347505951386
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HTMLValidator.Forms.MainForm.resources
HTMLValidator.Properties.Resources.resources
dr
[NBF]root.Data
gUFm
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: gDFs.pdb
Module Name
gDFs.exe
Full Name
gDFs.exe
EntryPoint
System.Void HTMLValidator.Program::Main()
Scope Name
gDFs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gDFs
Assembly Version
3.7.2.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
364
Main Method
System.Void HTMLValidator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HTMLValidator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
gDFs.exe
Full Name
gDFs.exe
EntryPoint
System.Void HTMLValidator.Program::Main()
Scope Name
gDFs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gDFs
Assembly Version
3.7.2.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
364
Main Method
System.Void HTMLValidator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HTMLValidator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HTMLValidator.Forms.MainForm.resources
HTMLValidator.Properties.Resources.resources
dr
[NBF]root.Data
gUFm
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙