Suspicious
Suspect

PE Executable
MD5: f6c255bffe3253d538fca1adbb0ccc60
Size: 790.53 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 f6c255bffe3253d538fca1adbb0ccc60
Sha1 2919235d611bb36611c1c47d53b52521b90d3a8b
Sha256 25e9013b961f8e4e49f65f9f29a08094929adf98c034a4536c871ab576ab5ae5
Sha384 6197b3275a20e93859435e2ab574bc9137a36933ef35c11e823234a6f3a7a207cfb40cc27ab962f736ff06da04837e88
Sha512 266ec5da9a0268eb81ec3ed10caf5e4e5580cb7d6b29fe4b2dea6ae65380ede36a1dc9058aa9608b0f6e1ed4ccced757ab12391aa5186707610050012b1c0434
SSDeep 24576:4z/Tq26QSS2pLoeX7nGY1xBaZsQwuK8XIjaKw:ueLDHnBles1uNIja
TLSH A6F402986B06C903C86A5B385775F27427BC1DEAE811D3074FECEDE7B966F255C08282
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MeditationTimer.Properties.Resources.resources
AEEP
[NBF]root.Data
[NBF]root.Data-preview.png
Square
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Re
Full Name
Re
EntryPoint
System.Void CLRIKeyValuePairI.ITransportHead::Main()
Scope Name
Re
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vpXh
Assembly Version
5.4.2.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
239
Main Method
System.Void CLRIKeyValuePairI.ITransportHead::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void c.SpecialNameAttrib::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
Re
Full Name
Re
EntryPoint
System.Void CLRIKeyValuePairI.ITransportHead::Main()
Scope Name
Re
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vpXh
Assembly Version
5.4.2.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
239
Main Method
System.Void CLRIKeyValuePairI.ITransportHead::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void c.SpecialNameAttrib::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MeditationTimer.Properties.Resources.resources
AEEP
[NBF]root.Data
[NBF]root.Data-preview.png
Square
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙