Suspicious
Suspect

cf564704f2e2d2f1ff6d0fb1c64656ba

PE Executable
MD5: cf564704f2e2d2f1ff6d0fb1c64656ba
Size: 808.45 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 cf564704f2e2d2f1ff6d0fb1c64656ba
Sha1 e7104205ba6c88eb4c3919c22b9329417859152a
Sha256 eb4f9a361af2fec77bcdea8b68e5aaf3d8e0ebbac245623975e99cf2a73861b3
Sha384 6e1b733b777157f6179eb8ae371dea37cc22b585916e0f7401e7bb985b245b18eca6b5a09d33867d15fdd83843767676
Sha512 6c52bf6f67eb32f64dbc3c09d30f23fa679c09acaa318401614d346e21e913ee914dea87df9403cd7fcf09255db044bd8b7ed53615dfa1ae222c191926be30f0
SSDeep 12288:RBBf7l9+WNSBRO8sa2nelFhCYbG8szlgrxlA3xNiVtOdLYD:Rvf7qWE3sa2e3hCYy8sZUHZteLY
TLSH 0C05125D6B4FDC22C9C12B701DA0E3B56378DE88E811C213CBFD6CDBB569E5269292C1
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
testeMatematico.Form1.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
CHT
[NBF]root.Data
timer1.TrayLocation
testeMatematico.Properties.Resources.resources
EarF
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
wBzQ.exe
Full Name
wBzQ.exe
EntryPoint
System.Void testeMatematico.Program::Main()
Scope Name
wBzQ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wBzQ
Assembly Version
2.2.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
104
Main Method
System.Void testeMatematico.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void testeMatematico.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
testeMatematico.Form1.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
CHT
[NBF]root.Data
timer1.TrayLocation
testeMatematico.Properties.Resources.resources
EarF
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙