Suspicious
Suspect

f8f3dc55c86a057880558111e2093354

PE Executable
MD5: f8f3dc55c86a057880558111e2093354
Size: 727.55 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 f8f3dc55c86a057880558111e2093354
Sha1 87ef22f6127f9682c260934532df951e416885ea
Sha256 dfb47b0d9362c1584332c02f37e614f8e54a3f9956cc3df38dbacd20c40c4db5
Sha384 7c7e912a172cd2aa4f415cfe349bcc172305089720678425c9a1b6264e46434a0b73ab765a323af7e8391ee06b980d89
Sha512 d5d474384332c1bdb663d49722c559f8a0f4e99dd413a8962d743809b28f8cced58900213c1887a6483f0e4830f4cbf86135d2659174b7de974ba67ec09b56fe
SSDeep 12288:RH2VHhgXMsdU7d8J9gs8Jojq07oQZcOzRQ8IWN/evWZf4LBhan2:NI2yeJ93COzdrpR
TLSH 9CF412256399D902C1E96BF02C30D7B493B56D98A411D70A9FEEBCEF3C31B105A913A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
UnitConverter.Forms.MainForm.resources
UnitConverter.Properties.Resources.resources
exFh
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: AveA.pdb
Module Name
AveA.exe
Full Name
AveA.exe
EntryPoint
System.Void UnitConverter.Program::Main()
Scope Name
AveA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
AveA
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
400
Main Method
System.Void UnitConverter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void UnitConverter.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
AveA.exe
Full Name
AveA.exe
EntryPoint
System.Void UnitConverter.Program::Main()
Scope Name
AveA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
AveA
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
400
Main Method
System.Void UnitConverter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void UnitConverter.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
UnitConverter.Forms.MainForm.resources
UnitConverter.Properties.Resources.resources
exFh
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙