Suspicious
Suspect

f176aeef4634cd1b7fe301e24be15f55

PE Executable
MD5: f176aeef4634cd1b7fe301e24be15f55
Size: 941.57 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 f176aeef4634cd1b7fe301e24be15f55
Sha1 ad52e5697ead5a0e09af44421950ddbbc630b085
Sha256 e85bc42c7456e0a394fd3ce094d79efbc3fa74d9bda545d204d6f45e371bd713
Sha384 b02fa1bcd1d37e8474e31a6e646dec9367f30a3474670e9eade60231859d79c9268fd4a6318436c071da9d695f597081
Sha512 dc7ac3533bd8739607beac5151b679dc7577511195558c63b9cc360e73a25cf65cb1178ee7f0649b05b5e849d37f3fc105e7523e217c060201901727b188bae7
SSDeep 24576:b2f7ATnjCKhndhsQd0IqFKFxAyagtH9Th:if7ATnjCendhsZ5UF0gtH
TLSH 911512016B2EEF22D9B50FF44971E37923B49E4DAA00D3174FE96CDBB0A5B012969353
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpaceCalculator.MainForm.resources
SpaceCalculator.Properties.Resources.resources
CHT
[NBF]root.Data
XxAu
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: BwON.pdb
Module Name
BwON.exe
Full Name
BwON.exe
EntryPoint
System.Void SpaceCalculator.Program::Main()
Scope Name
BwON.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BwON
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
414
Main Method
System.Void SpaceCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpaceCalculator.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpaceCalculator.MainForm.resources
SpaceCalculator.Properties.Resources.resources
CHT
[NBF]root.Data
XxAu
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙