Suspicious
Suspect

PE Executable
MD5: d7ddfcc98229f93608d6a3459f0e2a9e
Size: 711.68 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 d7ddfcc98229f93608d6a3459f0e2a9e
Sha1 3f2c35cc9847ef829519c3bea220e1a86edc6cd7
Sha256 752a406c3e6f56db0ca474d9ccd7b55b61ee5df6ab8d783092ea5df285a95153
Sha384 1ed9ffe462ef09a7f18ad60ea462ac63e0c96678d095638b3e0d03818303b2706ec2de1b920b207f1941b9a3b73ce744
Sha512 2f803d3fe1c1a7eed3915b70bf622d8575fa2367629e2f5cb056f0b4ffdb0005801cc09d20ff1b94cf9e0da2a945f3caca610027f4ef3a7d11fabe4c627f7802
SSDeep 12288:JMX0OTMfw2xTH5IEkAfIZtoYq72bo6bhhJBDwNut5svjOgWw/jw+TNX:JMgfvTCEvqoYqqPbvTDwNuvsvag97Tp
TLSH B2E422582E1AC81ACD119B741972F3B4113D5EDEA802DB179FFCAEEBB9BF9054C49081
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
HeRoSorter.MainForm.resources
$this.Icon
[NBF]root.IconData
Sort1
[NBF]root.Data
HeRoSorter.Properties.Resources.resources
DPDX
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
Bkin.exe
Full Name
Bkin.exe
EntryPoint
System.Void HeRoSorter.Program::Main()
Scope Name
Bkin.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Bkin
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
63
Main Method
System.Void HeRoSorter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HeRoSorter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
HeRoSorter.MainForm.resources
$this.Icon
[NBF]root.IconData
Sort1
[NBF]root.Data
HeRoSorter.Properties.Resources.resources
DPDX
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙