Suspicious
Suspect

PE Executable
MD5: c3f4419a2e3526c48291854532a8ad97
Size: 525.83 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 c3f4419a2e3526c48291854532a8ad97
Sha1 bd655c478c958891da50d38454a59af8eca7440a
Sha256 4de3da2145094b2d623f289bb59e0315edaa2a4820603e1b0384d96da159484c
Sha384 78ec01309a2529a6587d9f56f9a631199e5e0a6dd8e65dedc40ede850fd086552dc5ed09139123c9ed2beb5ec4b2ceda
Sha512 058ede89cdbf39258ce544a126ced92b64b48f4dc67e9f4c0ebf7afd6c487b81812af386544de729cfba2958b1b12e0316cdf30faab1731f7a3540cffee0dc23
SSDeep 12288:AmEYfHCtbZEe9CH7ublWeRxR2SqAfyMGAeSfaDhfHpRkR:kYfHOKe9CHS4+5qeGANatHi
TLSH 27B412B44664DA03C9C56BF305F0E339A7711E9EA122C62B46EEECFB79817616904372
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CampoMinatoEsagonale.FormContatoreMine.resources
CampoMinatoEsagonale.Properties.Resources.resources
DvdwLJ
[NBF]root.Data
[NBF]root.Data-preview.png
NH
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x7D000 size 13832 bytes
Info
PDB Path: ggzeov.pdb
Module Name
ggzeov.exe
Full Name
ggzeov.exe
EntryPoint
System.Void CampoMinatoEsagonale.Program::Main()
Scope Name
ggzeov.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ggzeov
Assembly Version
201.502.607.709
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
64
Main Method
System.Void CampoMinatoEsagonale.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CampoMinatoEsagonale.FormPrincipale::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ggzeov.exe
Full Name
ggzeov.exe
EntryPoint
System.Void CampoMinatoEsagonale.Program::Main()
Scope Name
ggzeov.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ggzeov
Assembly Version
201.502.607.709
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
64
Main Method
System.Void CampoMinatoEsagonale.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CampoMinatoEsagonale.FormPrincipale::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CampoMinatoEsagonale.FormContatoreMine.resources
CampoMinatoEsagonale.Properties.Resources.resources
DvdwLJ
[NBF]root.Data
[NBF]root.Data-preview.png
NH
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙