Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: b98984d3f003a61ac340a633c5944558
Size: 740.35 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b98984d3f003a61ac340a633c5944558
Sha1 886879dadbefe959ffac1f047f2293ab22919272
Sha256 5a30c4e68c8a9e2fa23d7176efd9f712624fb375d443c25b8829dd307e8b030d
Sha384 821439825fbe02219b253a6b0d605f928d3ebd7519b626a436b9594c51b85a560671657eb5ae8538c1a02727ce1119e2
Sha512 86683a74dc4a940d19dbf09dcac1ceb97891a34a64f35ad49017f8593b1167cf3c619ab382dee69e03a5343bfcd8ac6968e7c3dbf3b3ae609f43ec93671b9080
SSDeep 12288:hRR4A56CM7vvqTgdEE8WDb3NrQ065pnefTo+wU/EHXAEWIBUgXEpufC0OWTo:hRR4A56CeyTgiE8497+pneMScHwEUXYt
TLSH 44F412993397CA17E8A953F048B1D37053383DDEA421D3175EEAAED7393AB4059807A3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GradeCalculator.MainForm.resources
GradeCalculator.Properties.Resources.resources
FUyl
[NBF]root.Data
[NBF]root.Data-preview.png
KS
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: imWR.pdb
Module Name
imWR.exe
Full Name
imWR.exe
EntryPoint
System.Void GradeCalculator.Program::Main()
Scope Name
imWR.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
imWR
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
300
Main Method
System.Void GradeCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GradeCalculator.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙