Suspicious
Suspect

PE Executable
MD5: cfc73fe64a3613c0b727d3694eff1bc7
Size: 860.16 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 cfc73fe64a3613c0b727d3694eff1bc7
Sha1 3cae4484f6ffc2d9b8315d2699f47ec13093f9b3
Sha256 b4055118d7dc797e7cc480742781e29ca410e52f3ad7c07cb06ec13cc50ca3fd
Sha384 3473c19301140e999a6a051e9a2d46bfa381e853d082c54623a43fd3a91889129476b7ae0141d51c9d61620f35eaabab
Sha512 573b8c6df496bc99c41842d1619b28e5cdf0438050d79fdd7038f0ecc5e4c42b827c1f7d4e873f31d23be0bfe1f2116723a708ee6120e2f44239971d8716f81c
SSDeep 24576:OsB5y6ymqZ5O7F0AT9I9oUmasSFHOXAsHY:Osn8mF7rTqxnFW3
TLSH AE051221276BEC13C56D0BF016B0D3705778AE99B540D3539EFF6CEBB869B4025642A3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator.Form1.resources
$this.Icon
[NBF]root.IconData
msp
[NBF]root.Data
ExtractAssociatedIcon.Form1.resources
Calculator.Properties.Resources.resources
ieqV
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\cHcTzRzFZJ\src\obj\Debug\XeYr.pdb
Module Name
XeYr.exe
Full Name
XeYr.exe
EntryPoint
System.Void Calculator.Program::Main()
Scope Name
XeYr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XeYr
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
157
Main Method
System.Void Calculator.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Calculator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator.Form1.resources
$this.Icon
[NBF]root.IconData
msp
[NBF]root.Data
ExtractAssociatedIcon.Form1.resources
Calculator.Properties.Resources.resources
ieqV
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙