Suspicious
Suspect

c28bd998170f68d88caa8d3b4549ddad

PE Executable
MD5: c28bd998170f68d88caa8d3b4549ddad
Size: 800.77 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 c28bd998170f68d88caa8d3b4549ddad
Sha1 33fe08808b8cc9dd988ca0fba0bb64a419b5b356
Sha256 cbbec8fcc0e23e23bcdce82ab97533c7b49f0bcac924cf254a2a8d02b9594ac5
Sha384 d5dfabd32eee00d1782267d14bcd72f08c28c3eb320e1d6beed1beec9a8f2b0479a5604e0031aa8537c54e4e270743ee
Sha512 0561a9f5db11cbb0def1b12e69b2c61ac5fda2e18cde5822652420020bf3fe109d6784142c4534c3613eb50712e94d25e5d8cf7abd0ee3039801f38153a8584c
SSDeep 12288:z7F4szkvwj/A2BuYUjSBfo6JuIM6hzVZnlVgvwDyk6lAz5JGx++478sg330l:z7qZoD9ur2rM6/z8nkRFJL+/sg
TLSH C9050144F189FC0EC05A4774A970C0F00EB89EEAE602F69B9DD57EDF787AB301645286
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Magic8Ball2._0.Form1.resources
$this.Icon
[NBF]root.IconData
ball1
[NBF]root.Data
menuStrip1.TrayLocation
AsnanyDentalClinic.BufferingPage.resources
AsnanyDentalClinic.MyForms.RegisterationForm.resources
AsnanyDentalClinic.MyForms.SigninPage.resources
AsnanyDentalClinic.Properties.Resources.resources
clickAnother2
[NBF]root.Data
[NBF]root.Data-preview.png
clickSubmit2
[NBF]root.Data
[NBF]root.Data-preview.png
close
[NBF]root.Data
[NBF]root.Data-preview.png
close2
[NBF]root.Data
[NBF]root.Data-preview.png
dentist
[NBF]root.Data
[NBF]root.Data-preview.png
magicballDROP4
[NBF]root.Data
[NBF]root.Data-preview.png
sFYo
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\nPdqiPuEOz\src\obj\Debug\iwRe.pdb
Module Name
iwRe.exe
Full Name
iwRe.exe
EntryPoint
System.Void AsnanyDentalClinic.Program::Main()
Scope Name
iwRe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iwRe
Assembly Version
3.6.1.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
298
Main Method
System.Void AsnanyDentalClinic.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void AsnanyDentalClinic.BufferingPage::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
iwRe.exe
Full Name
iwRe.exe
EntryPoint
System.Void AsnanyDentalClinic.Program::Main()
Scope Name
iwRe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iwRe
Assembly Version
3.6.1.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
298
Main Method
System.Void AsnanyDentalClinic.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void AsnanyDentalClinic.BufferingPage::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Magic8Ball2._0.Form1.resources
$this.Icon
[NBF]root.IconData
ball1
[NBF]root.Data
menuStrip1.TrayLocation
AsnanyDentalClinic.BufferingPage.resources
AsnanyDentalClinic.MyForms.RegisterationForm.resources
AsnanyDentalClinic.MyForms.SigninPage.resources
AsnanyDentalClinic.Properties.Resources.resources
clickAnother2
[NBF]root.Data
[NBF]root.Data-preview.png
clickSubmit2
[NBF]root.Data
[NBF]root.Data-preview.png
close
[NBF]root.Data
[NBF]root.Data-preview.png
close2
[NBF]root.Data
[NBF]root.Data-preview.png
dentist
[NBF]root.Data
[NBF]root.Data-preview.png
magicballDROP4
[NBF]root.Data
[NBF]root.Data-preview.png
sFYo
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙