Suspicious
Suspect

PE Executable
MD5: f4b48496321018ee16c919231621c13b
Size: 1.09 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 f4b48496321018ee16c919231621c13b
Sha1 e2015ac4f699a07f7ea4c3ae9acfa930640fb965
Sha256 7f9d39908a024cc37cdece4ecc8aa724695ee2873d80ed4b1e7f8f8f3ee7ed5d
Sha384 6c7ef77cb1d6e2df01290118dea1c003050361cd6a0164af106732dda0c7f98c1e180ce3cf4e68c000e7397b5a03e619
Sha512 cd6c38dbbb5b7e03cda81a0cfa636c9533efeaa53cfe539063a73f2a77ccc3af795e1882fc460595ffc1d5fe10b7b94e234ed65f27af4f9c993f29ee7d2b6de6
SSDeep 24576:5PiTkw/IwLT3KwbyM/n9oRWrMhEzdCfGddSka:5KTkw/Pb9oRWIhKwE
TLSH 0D3512D82280C413CCA9C37C15B1D27547794C9ED961C292AFEEFDE375A47DEA808DA2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoinSimulator.Form3.resources
$this.Icon
[NBF]root.IconData
CoinSimulator.Properties.Resources.resources
CIisOEt
[NBF]root.Data
[NBF]root.Data-preview.png
GT8
[NBF]root.Data
images
[NBF]root.Data
[NBF]root.Data-preview.png
images__1_
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
LazyHelp
Full Name
LazyHelp
EntryPoint
System.Void CMSSCHEMAVERS.BindableVectorToListAdap::Main()
Scope Name
LazyHelp
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
evxEgoa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
158
Main Method
System.Void CMSSCHEMAVERS.BindableVectorToListAdap::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ISTOREENUMFILESFL.IRefl::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
LazyHelp
Full Name
LazyHelp
EntryPoint
System.Void CMSSCHEMAVERS.BindableVectorToListAdap::Main()
Scope Name
LazyHelp
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
evxEgoa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
158
Main Method
System.Void CMSSCHEMAVERS.BindableVectorToListAdap::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ISTOREENUMFILESFL.IRefl::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoinSimulator.Form3.resources
$this.Icon
[NBF]root.IconData
CoinSimulator.Properties.Resources.resources
CIisOEt
[NBF]root.Data
[NBF]root.Data-preview.png
GT8
[NBF]root.Data
images
[NBF]root.Data
[NBF]root.Data-preview.png
images__1_
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙