Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: f11a7b9639092de01f260dd0aa21d39a
Size: 1.04 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 f11a7b9639092de01f260dd0aa21d39a
Sha1 5960b5f16ab291a5c5841867d3f734e1aaaf949e
Sha256 673139dbfbd997edcebfe6d25b8cc2d006c59c752d89a84ef4136f1a5e876db0
Sha384 83cef8801512d5e063284d4e12524ac6c180b1376472c6364248974c5e5ef19e369247c9cf8deb9d2865a56b3f755a75
Sha512 cc494c8055636a49a905a55beabfca7752bdfb63ee0b9069dff706e162a0dc5b19133a1695990b4face773b8022fa7f422f06fed3f2892eba408d623ffe85964
SSDeep 24576:FWc23x7fYF7JcIwp9nVx1DZhmNHAZcdUnJ4MB:Fd23xMF7JcIwp9Vx1lhmNHecinJ3B
TLSH 0C25011C63C8C405C6BF9376A0B2E171037ABD5BF978D36D06C9BCEB3AA1B025945726
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AnalyzeGraphics.MainForm.resources
$this.Icon
[NBF]root.IconData
bindingNavigatorAddNewItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorDeleteItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveFirstItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveLastItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveNextItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMovePreviousItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
AnalyzeGraphics.Properties.Resources.resources
JeHhh
[NBF]root.Data
[NBF]root.Data-preview.png
TCA
[NBF]root.Data
Name Value
Module Name
GOxpr.exe
Full Name
GOxpr.exe
EntryPoint
System.Void AnalyzeGraphics.Program::Main()
Scope Name
GOxpr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
GOxpr
Assembly Version
4.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
760
Main Method
System.Void AnalyzeGraphics.Program::Main()
Main IL Instruction Count
37
Main IL
nop <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
ldnull <null>
ldftn System.Void AnalyzeGraphics.Program::Application_ThreadException(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
nop <null>
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void AnalyzeGraphics.Program::CurrentDomain_UnhandledException(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
nop <null>
newobj System.Void AnalyzeGraphics.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0069: ret
stloc.0 <null>
nop <null>
ldstr Critical error during application startup: 
ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
ldstr Application Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0069: ret
ret <null>
PDB Path PATH
GOxhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙