Suspicious
Suspect

PE Executable
MD5: db972e8a15ffb1de154b4cfbcfad73bf
Size: 708.61 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 db972e8a15ffb1de154b4cfbcfad73bf
Sha1 d072b0127213128dfd2f1e11424570f70b7bb933
Sha256 39c4d5fa49fbd60a79d81d530c51ec308030bb29cd7e5ff3e618c51f1c252dd9
Sha384 039f625280b2c0c7b1c566c88c16ea44dc4a0a47e44f64adcfb73957e30216476a5cc52b497ed0b9aab552937d68631e
Sha512 0c816e04f87ba4e0a7377bf737b20d4d3202bae80bf2fa529698061c6e4e120141c8fc87a2d0a6ea4266e46969f6b376bfacded128723559ffaa1ce04bd3bac3
SSDeep 12288:/5WNfE3HRBiKCE76mhscR5NaZ58zN9gQ2kkJ7HdspcTh++NGmqp:c23HLCqjDRMtQzW796cT8+NGmu
TLSH 92E412507B15C603D2AA6BB66861E17113B8BE5EB820E3569FD57EEF7271F004C48B23
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Modular_Exponentiation.Forms.MainForm.resources
Modular_Exponentiation.Properties.Resources.resources
CpaG
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: iahs.pdb
Module Name
iahs.exe
Full Name
iahs.exe
EntryPoint
System.Void Modular_Exponentiation.Program::Main()
Scope Name
iahs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iahs
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
334
Main Method
System.Void Modular_Exponentiation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Modular_Exponentiation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
iahs.exe
Full Name
iahs.exe
EntryPoint
System.Void Modular_Exponentiation.Program::Main()
Scope Name
iahs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iahs
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
334
Main Method
System.Void Modular_Exponentiation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Modular_Exponentiation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Modular_Exponentiation.Forms.MainForm.resources
Modular_Exponentiation.Properties.Resources.resources
CpaG
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙