Suspicious
Suspect

f53274f91f961047187627788af9d702

PE Executable
MD5: f53274f91f961047187627788af9d702
Size: 792.06 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 f53274f91f961047187627788af9d702
Sha1 c4c1058bee17ec3c14c86c1e9620c17964b3a958
Sha256 e8ce2e55e136691181df4fbc28e02a122805f3f5ca753b6ad1c1b04daef16662
Sha384 04ddb173d5c73542c1625df0b7955af293ab6d240aeff86751133d92bf57c52af91950998be2b982453e6dec45494d13
Sha512 605bd8da761e6717d311779f2318beeab0aca135e133baeef07009103808f6f243ef96caf91a0ad8677d93e40330651e20119e748d5fe9d01c017bc37abe0dcf
SSDeep 24576:6Zf7HPNmQCFPxsqZ1po3tmocaTIcjQLaeqG:wf7HjCFmU3o3NgcULaeq
TLSH 44F401052B29EF12E8A21BF149B1E3B613B4AE5DA910D3074FE97CDB747AF442509B43
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpaceCalculator.MainForm.resources
SpaceCalculator.Properties.Resources.resources
CHT
[NBF]root.Data
KydO
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: LxyC.pdb
Module Name
LxyC.exe
Full Name
LxyC.exe
EntryPoint
System.Void SpaceCalculator.Program::Main()
Scope Name
LxyC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LxyC
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
414
Main Method
System.Void SpaceCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpaceCalculator.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpaceCalculator.MainForm.resources
SpaceCalculator.Properties.Resources.resources
CHT
[NBF]root.Data
KydO
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙