Suspicious
Suspect

d9e50b1a5d87d2e2c2742b52a552f074

PE Executable
MD5: d9e50b1a5d87d2e2c2742b52a552f074
Size: 699.9 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 d9e50b1a5d87d2e2c2742b52a552f074
Sha1 a2d805c470d13c18689e65828f5a930f1069468a
Sha256 d87de6be63c49499dfe482bfdafbdca13760efb66c2d8af6950919f01f52608c
Sha384 956c0d16659e6d3bc0fec18e3c99d419b92faff09a4c2203238c10c079832e2b2dde158a29166ad9760489702287abe7
Sha512 3be7b3660c6282335adb01d87ba6d4830ef148bff31846ccd36ba129f70b60266e647462b174d5ac499165828318b773b634652baa09a9d765ba36cc074364e1
SSDeep 12288:aBBf7dAe+zz0Fv2IhEuSVASCwnxDRuKUl/sqljRcAuC:avf7yNAFv2ESVAgxluKUUql9c
TLSH CFE402286B4BDD12D9C16BB10990E3B513389D0CE920D2178BFEADDBB879F527D482D1
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
testeMatematico.Form1.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
CHT
[NBF]root.Data
timer1.TrayLocation
testeMatematico.Properties.Resources.resources
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
qtbJ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
zBfU.exe
Full Name
zBfU.exe
EntryPoint
System.Void testeMatematico.Program::Main()
Scope Name
zBfU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zBfU
Assembly Version
2.2.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
104
Main Method
System.Void testeMatematico.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void testeMatematico.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
testeMatematico.Form1.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
CHT
[NBF]root.Data
timer1.TrayLocation
testeMatematico.Properties.Resources.resources
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
qtbJ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙