Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: e609ca61ec8c974a1d5e2df918e089ef
Size: 835.58 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 e609ca61ec8c974a1d5e2df918e089ef
Sha1 73c0e98bc11b30ddc00d2dd294d3fe649faa2800
Sha256 a4e1ceb8458e0bca4119adb33ded5b1ef154f0ba69594b2079fbbcfb48cbe4ce
Sha384 b01e3c74e092fcdf3ccb024d023251aebb11132951c4e25a6f2864afbcc15d3dafebee84c2f3f55fd82ee42718d96141
Sha512 033e0e14ce1a74702f90fe53e6317485d9dd3e82be064d8d4c7dddaa86e93bc7feca0dea009f7c01c30a6317c527ebc59501c649bde4739834fe77c2204af762
SSDeep 12288:1znnf4iy7vPjKGNVbMvft6j6BKpRMGWY5mMMh8Z5CPPO5+ODjf0vv7:Bnnf4iyzLfXbM96jqoA6mn/Vmjfov7
TLSH 250501853655C903C46006F4892AE7FCA3791F9AB831EF12BEE57DCB3835714A18B293
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator_Project.Calculator.resources
$this.Icon
[NBF]root.IconData
greyder
[NBF]root.Data
Login_And_Register_Form.registerForm.resources
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Login_And_Register_Form.frmLogin.resources
Login_And_Register_Form.Properties.Resources.resources
OtS
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
rrE.exe
Full Name
rrE.exe
EntryPoint
System.Void Login_And_Register_Form.Program::Main()
Scope Name
rrE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rrE
Assembly Version
6.3.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
174
Main Method
System.Void Login_And_Register_Form.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Login_And_Register_Form.registerForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
rrhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙