Suspicious
Suspect

d8c41c2f0d3b3073e8dd25de2d802346

Share on LinkedIn
Print
PE Executable
MD5: d8c41c2f0d3b3073e8dd25de2d802346
Size: 1.15 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 d8c41c2f0d3b3073e8dd25de2d802346
Sha1 53e3e8c898d89121498233f7a32a36ef63c9052f
Sha256 caac6296da90bd564851a40bf1df66a2abb7309252d9f37a61536049b05e058d
Sha384 fd4b9518941c760fbcccdc05dc167faed54c3a94d9da31c2244e3ce8600580e70301e8c015ad6753b5767b7f75a07744
Sha512 6d91098382aece2b9813f91dc2947c737b22d7188e18cfc890e8eb706a659e85d2ddb44f160ea0485e8cf916d7de5a7e585dc510ef36ee0152df4ecca49849bd
SSDeep 24576:H3AQmyZhVuDpjFysIhajUHp8rSCK/zzJ/O6ht1W9qQONuBP:H33my9uljMssi2p8rSphhhTnuBP
TLSH 853501186388C409C6BE4773A4B5E17647B5BE1BF574D36D0AD9BCAF3EB0702184932A
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AnalyzeGraphics.MainForm.resources
$this.Icon
[NBF]root.IconData
bindingNavigatorAddNewItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorDeleteItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveFirstItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveLastItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveNextItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMovePreviousItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
AnalyzeGraphics.Properties.Resources.resources
DWncx
[NBF]root.Data
[NBF]root.Data-preview.png
TCA
[NBF]root.Data
Name Value
Module Name
zSVsl.exe
Full Name
zSVsl.exe
EntryPoint
System.Void AnalyzeGraphics.Program::Main()
Scope Name
zSVsl.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zSVsl
Assembly Version
4.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
760
Main Method
System.Void AnalyzeGraphics.Program::Main()
Main IL Instruction Count
37
Main IL
nop <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
ldnull <null>
ldftn System.Void AnalyzeGraphics.Program::Application_ThreadException(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
nop <null>
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void AnalyzeGraphics.Program::CurrentDomain_UnhandledException(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
nop <null>
newobj System.Void AnalyzeGraphics.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0069: ret
stloc.0 <null>
nop <null>
ldstr Critical error during application startup: 
ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
ldstr Application Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0069: ret
ret <null>
PDB Path PATH
zSVhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙