Suspicious
Suspect

PE Executable
MD5: de3f2c772101a6ca9c18091bdb4e5019
Size: 896 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 de3f2c772101a6ca9c18091bdb4e5019
Sha1 d2212adf7fee88b1a9b43e6519b70cf4d02457cd
Sha256 92196af46e360781ef13051a02c0bb5cffe02c8e36e791edcf3b85ef81f79ff5
Sha384 d086e6b8a293e5f50fe1193ac3348b34ffc7a24824ada13ca55176ff9465b2c09c2a79358c3dadb999af320aa6c4757e
Sha512 4f6d228d77e6c8b46f63b21bf2411869d88da7666e51767827f223dd7473b3006bfbb6bcc37f553a9f3d53d5cfb0f2bdc608eb6af3c451ff866beb90c821a9d5
SSDeep 12288:k5t0f/1P1s4EKsszTbQZq8JdNsxJwAPkJ9TRD3wNsSetBeGLMD2qdFT3+8MulOC/:k5+Ts4EKfz5afMJ/gHDM1Cu7+tuM4
TLSH 8B15222EA907D917C1868FF1AC21E77433B45E9DB415D6079FEE6CEBB53A60686003C2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Carubbi.MetroLayoutEngine.PromptDialog.resources
Carubbi.MetroLayoutEngine.MetroLayoutForm.resources
$this.Icon
[NBF]root.IconData
shp
[NBF]root.Data
Carubbi.MetroLayoutEngine.Properties.Resources.resources
JKJn
[NBF]root.Data
[NBF]root.Data-preview.png
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\wkNxtTcnHj\src\obj\Debug\Faxg.pdb
Module Name
Faxg.exe
Full Name
Faxg.exe
EntryPoint
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Scope Name
Faxg.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Faxg
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
47
Main Method
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Carubbi.MetroLayoutEngine.MetroLayoutForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
Faxg.exe
Full Name
Faxg.exe
EntryPoint
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Scope Name
Faxg.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Faxg
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
47
Main Method
System.Void Carubbi.MetroLayoutEngine.MainC::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Carubbi.MetroLayoutEngine.MetroLayoutForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Carubbi.MetroLayoutEngine.PromptDialog.resources
Carubbi.MetroLayoutEngine.MetroLayoutForm.resources
$this.Icon
[NBF]root.IconData
shp
[NBF]root.Data
Carubbi.MetroLayoutEngine.Properties.Resources.resources
JKJn
[NBF]root.Data
[NBF]root.Data-preview.png
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙