Suspicious
Suspect

PE Executable
MD5: c02dceb19777b922e01e19a68a260ec2
Size: 529.93 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 c02dceb19777b922e01e19a68a260ec2
Sha1 00d8b976a5a87281c45244f662b192b0545473ae
Sha256 76cff505d993baaecd718a3b0de1814da0aef73ce932d95bacbc6d842db38807
Sha384 862ab7b0f155a3a9580897c839835f1634d942a02e5c6bbe63c5d9695bb98b066780f945d1f46657dbecdb6fdafcae35
Sha512 fe95a79f7ad4f5abd98164e4b95f76b780ffed2fd5467a154b637eaab3b53266a1af2c984bc0382856f163847675ea5d0307f3f64e2421eb6cc1f82b635ce6b9
SSDeep 12288:AGtAJ+/JZjuXkz4HPOWWGLzyt7tNog8q6f58DFTqhan2KkR:AGtAYJZSI4vOPGKptNoBB8t4
TLSH D4B4F19526E9D400E1F67F7428B6D3B58B7B7E89A830C35647E87CDF3D2271068603A6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
enxZ
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x7E000 size 13832 bytes
Info
PDB Path: fsbk.pdb
Module Name
fsbk.exe
Full Name
fsbk.exe
EntryPoint
System.Void StudyGuide.Program::Main()
Scope Name
fsbk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
fsbk
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
101
Main Method
System.Void StudyGuide.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void StudyGuide.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
fsbk.exe
Full Name
fsbk.exe
EntryPoint
System.Void StudyGuide.Program::Main()
Scope Name
fsbk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
fsbk
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
101
Main Method
System.Void StudyGuide.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void StudyGuide.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
enxZ
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙