Suspicious
Suspect

PE Executable
MD5: efbf05f3d5d9982a1a544bdf9b933c35
Size: 990.72 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 efbf05f3d5d9982a1a544bdf9b933c35
Sha1 a1ebc02f7872decde42a8ed1d40bb1039ff26601
Sha256 82dbec85d38c90b698f12ae23f185b3f5a76b15b0f544530ddb9750c8fb80d6f
Sha384 757561a0f6c709706a54e90562fa4a463f03261529ab15510d8b660846609487174a52a88567586935891e343450d59f
Sha512 03a709223905ce068675b6fe14cd0b23b77b4a76571ab079305e8b3a0e74a6d8139e08ce16cf4d52cffd02e9d1004e72882de51f3d595e7d55c301f5c89cb46a
SSDeep 24576:aZ3aludUimaydppGlbfnnpBXurW1+aw7qc9xVb6D:Nu7ma31nXwW1+3d9xl6
TLSH CA2522B01662EE15E8E287F15950E3B303325EDC9821D30EADDEECEBB91AB1C19553D1
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PuhonRM.Properties.Resources.resources
myaF
vgx
PuhonRM.AddItem.resources
PuhonRM.ItemView.resources
btnAdd.Image
Name Value
Module Name
moXs.exe
Full Name
moXs.exe
EntryPoint
System.Void PuhonRM.Program::Main()
Scope Name
moXs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
moXs
Assembly Version
1.6.2010.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
107
Main Method
System.Void PuhonRM.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PuhonRM.ItemView::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
moXs.exe
Full Name
moXs.exe
EntryPoint
System.Void PuhonRM.Program::Main()
Scope Name
moXs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
moXs
Assembly Version
1.6.2010.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
107
Main Method
System.Void PuhonRM.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PuhonRM.ItemView::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PuhonRM.Properties.Resources.resources
myaF
vgx
PuhonRM.AddItem.resources
PuhonRM.ItemView.resources
btnAdd.Image
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
efbf05f3d5d9982a1a544bdf9b933c35
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
efbf05f3d5d9982a1a544bdf9b933c35
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙