Suspicious
Suspect

PE Executable
MD5: ca8d663e2ea348134ae2b315199fb5ed
Size: 777.22 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 ca8d663e2ea348134ae2b315199fb5ed
Sha1 7c0a6477c1e4cdaf30a9a7ca9ba6c9c843f193ee
Sha256 5363b10f3f97233cd110918e516973fadba750d34b48af44fd82db21fd16fecb
Sha384 23f00c54332a6d366e443f88a67775b157a80290355a772fed7b6a1d54902cab5af903d2005115d9eb17c84ac3431fd0
Sha512 ca6b058ee134ba21383c7b1d7a101ab497dea19888c4d1f5ca291b4f88e8b77a606f71be3611a5153b92694d286e039dc5adda1dc6a155227ff7d70674080e18
SSDeep 12288:+T/KqOZQ8945kAysmDfPPlZl/R5m6hGGJgDFPl0zqynNJY2/:2CRQugkTfPPld5m6cGJmFazqM/
TLSH F0F4F114226ACB05E5764FF51A71E2B01B78BE9AE912E70B9FC53EDFB836B105940343
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EventLogAnalyzer.Forms.MainForm.resources
EventLogAnalyzer.Properties.Resources.resources
IO
[NBF]root.Data
RBey
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: dOyX.pdb
Module Name
dOyX.exe
Full Name
dOyX.exe
EntryPoint
System.Void EventLogAnalyzer.Program::Main()
Scope Name
dOyX.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dOyX
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
341
Main Method
System.Void EventLogAnalyzer.Program::Main()
Main IL Instruction Count
27
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
nop <null>
newobj System.Void EventLogAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0045: ret
stloc.0 <null>
nop <null>
ldstr An unexpected error occurred:


ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
ldstr 

The application will now close.
call System.String System.String::Concat(System.String,System.String,System.String)
ldstr Critical Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0045: ret
ret <null>
Module Name
dOyX.exe
Full Name
dOyX.exe
EntryPoint
System.Void EventLogAnalyzer.Program::Main()
Scope Name
dOyX.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dOyX
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
341
Main Method
System.Void EventLogAnalyzer.Program::Main()
Main IL Instruction Count
27
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
nop <null>
newobj System.Void EventLogAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0045: ret
stloc.0 <null>
nop <null>
ldstr An unexpected error occurred:


ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
ldstr 

The application will now close.
call System.String System.String::Concat(System.String,System.String,System.String)
ldstr Critical Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0045: ret
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EventLogAnalyzer.Forms.MainForm.resources
EventLogAnalyzer.Properties.Resources.resources
IO
[NBF]root.Data
RBey
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙