Suspicious
Suspect

PE Executable
MD5: cc8dda6a58ba1371eefc73ec689b3945
Size: 921.09 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 cc8dda6a58ba1371eefc73ec689b3945
Sha1 5ea24c6163c12d2a9c2acf620c36d36870a698f5
Sha256 042d135796e15d95ea837efb356fea090375320e569d9dee4b88a5f1b82bcb63
Sha384 feec4a76f0cf966e6ebd10cf768b706d1eb6f97d416d07ee2bea407fcc021ad86562c30b40e6a6152de1f8da7168f202
Sha512 2c848d29121ab16d276acb047f53493857acd7b8e855f8b93e3524657e0de9c6e541dd20ae83292654e5e2401de745634e36d46b44a85dfc610564ee28456b9a
SSDeep 24576:vHmLwpK3lRJ+jxOgbPcDmjn6RmzkZ/GimiGM8:vHwLGaw6RmzkZ/GfVM
TLSH AB151266264DD807C1D66BF08EE1D3BC13745ECDA421D38A9EE99CCB7D6875852803E3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DirectoryPlus.MainForm.resources
DirectoryPlus.Properties.Resources.resources
gilek
[NBF]root.Data
kpVX
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: yeBE.pdb
Module Name
yeBE.exe
Full Name
yeBE.exe
EntryPoint
System.Void DirectoryPlus.Program::Main()
Scope Name
yeBE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yeBE
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
161
Main Method
System.Void DirectoryPlus.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void DirectoryPlus.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
yeBE.exe
Full Name
yeBE.exe
EntryPoint
System.Void DirectoryPlus.Program::Main()
Scope Name
yeBE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yeBE
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
161
Main Method
System.Void DirectoryPlus.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void DirectoryPlus.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DirectoryPlus.MainForm.resources
DirectoryPlus.Properties.Resources.resources
gilek
[NBF]root.Data
kpVX
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙