Suspicious
Suspect

PE Executable
MD5: f4302131044ad2a9730f8865e69ac8ab
Size: 741.89 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 f4302131044ad2a9730f8865e69ac8ab
Sha1 07a8cb7cb1d57b6d0976d56e4a97644111db4b6a
Sha256 104d7263dd77981b760c26e0fb61986e6aa2a3e86eab2ae4bc7468cf28eaf902
Sha384 a37b60697e13a5ee5fc035f17554eadf3e2f91da0318a1bcddfbe3a69887dca1becab98945da5d995dcb5405f6489f62
Sha512 29fdd7969d566c94f863382456a2c49ba937662db0f315a81138fd86ffed9c3d293150ebc7d0497d6da011d6766a3822c58d450684f73c771c4ce1c14b2f24a5
SSDeep 12288:Ipcszdvtir0dhtKrLdPyr9+H+w8GSaL3+79zMPEmrxwZHTgYsGNPT3S:Im0YrOr9M+uSTNMPEmd4zgGT3
TLSH 5AF4125632A9C903D5F157F09EB1E3FC5378AF896001E3578EFAAEDBB871B006690191
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DirectoryPlus.MainForm.resources
DirectoryPlus.Properties.Resources.resources
gilek
[NBF]root.Data
wDxS
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: cocu.pdb
Module Name
cocu.exe
Full Name
cocu.exe
EntryPoint
System.Void DirectoryPlus.Program::Main()
Scope Name
cocu.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
cocu
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
161
Main Method
System.Void DirectoryPlus.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void DirectoryPlus.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
cocu.exe
Full Name
cocu.exe
EntryPoint
System.Void DirectoryPlus.Program::Main()
Scope Name
cocu.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
cocu
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
161
Main Method
System.Void DirectoryPlus.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void DirectoryPlus.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DirectoryPlus.MainForm.resources
DirectoryPlus.Properties.Resources.resources
gilek
[NBF]root.Data
wDxS
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙