Suspicious
Suspect

PE Executable
MD5: c8c5f98900ad9881d7062eb288423ec7
Size: 103.04 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 c8c5f98900ad9881d7062eb288423ec7
Sha1 4ab5fc8444f81a5ceb3b939ab37fdf565cbf5c70
Sha256 717523d724e1a190e26629f839ef7acefc4ece512c0ae447d3ef453739e14203
Sha384 5e300bda52ffeab75e35f8c6c0aefcbc5bd23dba44e2356cbd4b91f1c880e61cb21b576737d5331bec60d5dedc0cff1a
Sha512 f177ebd5ff00aec1b1511cb0feee7953fe4c3b3c43c5ceeb4ce1b873216bf3b9a7d4e85e0a91f196f4dcb715e1b4af435c1a9db4e57c9429c56a7efde416b46a
SSDeep 1536:WAp5eznKUlIOp3YjVCguHEvQEbFqVC3woFRKpT4Xi:d5eznsjsguGDFqGS
TLSH 0CA3DB387D952133C67EC1F689E90A8AEB69223F3191E9ED4CA742C418B2F156DC1D1F
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
26fc2.resources
1973c.png
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
1.exe
Full Name
1.exe
EntryPoint
System.Void MusicExpress.Program::Main()
Scope Name
1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
1
Assembly Version
1.28.14.52
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
1178
Main Method
System.Void MusicExpress.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void MusicExpress.MusicExpressMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
1.exe
Full Name
1.exe
EntryPoint
System.Void MusicExpress.Program::Main()
Scope Name
1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
1
Assembly Version
1.28.14.52
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
1178
Main Method
System.Void MusicExpress.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void MusicExpress.MusicExpressMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
26fc2.resources
1973c.png
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙