Suspicious
Suspect

PE Executable
MD5: b5bcd6febecd3f21b8a7c19525ccb0d8
Size: 963.08 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b5bcd6febecd3f21b8a7c19525ccb0d8
Sha1 aa01d8b189e8480ca12543b54197c4044b787095
Sha256 1bfc67fda739fb4b9d8ec51ab705c1348396d37eb76be0035183e12b26c7f6ea
Sha384 13ff98bba9229224d92c83a6d81e062cc2ceaa46c81e7bcdbd2e4859dc8e8e8e54619b7b6293a3c4dac1b33b6876ee6d
Sha512 1e946fabf64787cdcc78fe1b5078c27c066fd490ace0a5e725136964d8417afe2dab767156b6257ae4cd8927821efcfc3f145502d2e4289038f8776eb084841f
SSDeep 24576:6wNNaaPSvM7YjVNKkeScD9O192e5fzlIOqf:RzV4VNKXSwexl1qf
TLSH 9825236167F8CA12E0BA9BF1A471E13267363E19F152E212ADC6CDDF3408BF05B45B12
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ScientificCalculator.Forms.GraphPlotterForm.resources
Scientific_Calc.Properties.Resources.resources
PIP
[NBF]root.Data
SQxT
[NBF]root.Data
[NBF]root.Data-preview.png
t1
[NBF]root.Data
[NBF]root.Data-preview.png
t2
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
meLE.exe
Full Name
meLE.exe
EntryPoint
System.Void ScientificCalculator.Program::Main()
Scope Name
meLE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
meLE
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
380
Main Method
System.Void ScientificCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ScientificCalculator.Forms.MainCalculatorForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
meLE.exe
Full Name
meLE.exe
EntryPoint
System.Void ScientificCalculator.Program::Main()
Scope Name
meLE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
meLE
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
380
Main Method
System.Void ScientificCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ScientificCalculator.Forms.MainCalculatorForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
mehuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ScientificCalculator.Forms.GraphPlotterForm.resources
Scientific_Calc.Properties.Resources.resources
PIP
[NBF]root.Data
SQxT
[NBF]root.Data
[NBF]root.Data-preview.png
t1
[NBF]root.Data
[NBF]root.Data-preview.png
t2
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
mehuhuhuhu
b5bcd6febecd3f21b8a7c19525ccb0d8
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙