Suspicious
Suspect

PE Executable
MD5: b98984d3f003a61ac340a633c5944558
Size: 740.35 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b98984d3f003a61ac340a633c5944558
Sha1 886879dadbefe959ffac1f047f2293ab22919272
Sha256 5a30c4e68c8a9e2fa23d7176efd9f712624fb375d443c25b8829dd307e8b030d
Sha384 821439825fbe02219b253a6b0d605f928d3ebd7519b626a436b9594c51b85a560671657eb5ae8538c1a02727ce1119e2
Sha512 86683a74dc4a940d19dbf09dcac1ceb97891a34a64f35ad49017f8593b1167cf3c619ab382dee69e03a5343bfcd8ac6968e7c3dbf3b3ae609f43ec93671b9080
SSDeep 12288:hRR4A56CM7vvqTgdEE8WDb3NrQ065pnefTo+wU/EHXAEWIBUgXEpufC0OWTo:hRR4A56CeyTgiE8497+pneMScHwEUXYt
TLSH 44F412993397CA17E8A953F048B1D37053383DDEA421D3175EEAAED7393AB4059807A3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GradeCalculator.MainForm.resources
GradeCalculator.Properties.Resources.resources
FUyl
[NBF]root.Data
[NBF]root.Data-preview.png
KS
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: imWR.pdb
Module Name
imWR.exe
Full Name
imWR.exe
EntryPoint
System.Void GradeCalculator.Program::Main()
Scope Name
imWR.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
imWR
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
300
Main Method
System.Void GradeCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GradeCalculator.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GradeCalculator.MainForm.resources
GradeCalculator.Properties.Resources.resources
FUyl
[NBF]root.Data
[NBF]root.Data-preview.png
KS
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙