Suspicious
Suspect

PE Executable
MD5: da8353f8d4c8a668cb388871ddecd5c6
Size: 1.09 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 da8353f8d4c8a668cb388871ddecd5c6
Sha1 4f01c576b49387cb5b4b1cfa2e0d0e11fbcd0bc2
Sha256 55f142f550fa6dcfd1468195bc9b9fdca87714a06e5a8370152119fb10405b32
Sha384 0c96b6b79934cf65b6f151a1da1023fda86463444ce50fe50ae4fcf9f42926753f5b1dab5bf1e832a354ed79d721d87d
Sha512 000e26067981663020b539b96c7e5f0c3561895f9cba27151e3c268537aa78abefbc8f4b30a638af0dadda1bda914106e7865ce261e1177db0e23f55e98d985c
SSDeep 24576:+1PddCWv8WGFYSEvcx75dfemIFY47uowM31a:+P05ZTdGbFZuowM
TLSH 283523527655CA06C5BE4BF909B1E73417F6BC9EA801E3168FFD8DEFB90078128052A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterReminder.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
WaterReminder.Form1.resources
WaterReminder.Properties.Resources.resources
GT8
[NBF]root.Data
YJmyNxc
[NBF]root.Data
[NBF]root.Data-preview.png
images
[NBF]root.Data
[NBF]root.Data-preview.png
images__1_
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Impl
Full Name
Impl
EntryPoint
System.Void FileDialogPermissionAttrib.EventCacheEn::Main()
Scope Name
Impl
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gFOiyox
Assembly Version
2.0.3.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
322
Main Method
System.Void FileDialogPermissionAttrib.EventCacheEn::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ConfigNodeSubT.DelegateSerializationHol::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
Impl
Full Name
Impl
EntryPoint
System.Void FileDialogPermissionAttrib.EventCacheEn::Main()
Scope Name
Impl
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gFOiyox
Assembly Version
2.0.3.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
322
Main Method
System.Void FileDialogPermissionAttrib.EventCacheEn::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ConfigNodeSubT.DelegateSerializationHol::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WaterReminder.AboutBox1.resources
logoPictureBox.Image
[NBF]root.Data
[NBF]root.Data-preview.png
WaterReminder.Form1.resources
WaterReminder.Properties.Resources.resources
GT8
[NBF]root.Data
YJmyNxc
[NBF]root.Data
[NBF]root.Data-preview.png
images
[NBF]root.Data
[NBF]root.Data-preview.png
images__1_
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙