Suspicious
Suspect

PE Executable
MD5: d25e0bb5a85a1746d131a5f0bc6d2248
Size: 753.15 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 d25e0bb5a85a1746d131a5f0bc6d2248
Sha1 c86102bfe5de45d81af1aeed03cc366bde5de82c
Sha256 36280a1bd2e33ed7ea30c933a722695cb37f2dec3dcc1ab69bceb3b954e84d98
Sha384 5eab2f9033014af2044689ce2ae68eba02a011643185ad34e4f5bdb668a012fd917ce3747976fe77a3a56bb42627479f
Sha512 a789c18d3d456b572f8e47e380ffa9cae1321ec1dd68ef012a4cc4eec689710df2ac6cf2225be3d7f9e377382678ec71aaddc7d9789240faa6af72a75695fedf
SSDeep 12288:d3L/rb8WkKLWeiOTTY7ZvMZyXkYk1NCQgz6+yDR3FSSRZraZOJdlS/poSyW8N:V7v+KL7E9EZGk1kYBFL3r7dqoS3
TLSH 20F412681B2DDF07D4E21BF406B1E2B02374AE5DE411D2068FE9BCDFB469B572868253
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FibonacciDrawer.IterationControlForm.resources
FibonacciDrawer.Properties.Resources.resources
NI
[NBF]root.Data
wpJH
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: SHCi.pdb
Module Name
SHCi.exe
Full Name
SHCi.exe
EntryPoint
System.Void FibonacciDrawer.Program::Main()
Scope Name
SHCi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
SHCi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
143
Main Method
System.Void FibonacciDrawer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FibonacciDrawer.MainSpiralForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
SHCi.exe
Full Name
SHCi.exe
EntryPoint
System.Void FibonacciDrawer.Program::Main()
Scope Name
SHCi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
SHCi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
143
Main Method
System.Void FibonacciDrawer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FibonacciDrawer.MainSpiralForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FibonacciDrawer.IterationControlForm.resources
FibonacciDrawer.Properties.Resources.resources
NI
[NBF]root.Data
wpJH
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙