Suspicious
Suspect

PE Executable
MD5: fd6cce2db6576caef5ce3d336d28eed8
Size: 549.89 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 fd6cce2db6576caef5ce3d336d28eed8
Sha1 47f4fb0731b534dd87bdb5c7795cb1d9ab363a90
Sha256 26e7f73744ff89320d8e9c39760db8dc4f4e0865c1e18423d60926b3de522b47
Sha384 ad4d23df66d7e67f1b6147f61bad32c94197b27f8147a97ce8ccb014cb9b7117b326f033763619c3e6eb5d94f583df21
Sha512 afda2bba30b815fe05b214ccaacc1c4adcfa00cdf6e4ca10a6bfe60dfc57ed72c83f49f94d26467db13ff74bc8a5cabeb0c12e2fc3676a7db0a441c387c2026f
SSDeep 12288:IuJznnf6hPKV5BSCyFY7UY7sMDSQJFg/xqLLWSdqXsGYNl14:Iutnnf6huHyFYN/SQfgcOSXN
TLSH CFC4F1443356DA07D4AA5BF05DB2E37807BA6E89A810D30B8EEBBDD73C31B441985397
PeID
Armadillo v4.x
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNetworkAnalyzer.Forms.MainForm.resources
SmartNetworkAnalyzer.Properties.Resources.resources
greyder
[NBF]root.Data
uOA
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: PZF.pdb
Module Name
PZF.exe
Full Name
PZF.exe
EntryPoint
System.Void SmartNetworkAnalyzer.Program::Main()
Scope Name
PZF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PZF
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void SmartNetworkAnalyzer.Program::Main()
Main IL Instruction Count
26
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
nop <null>
newobj System.Void SmartNetworkAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0040: ret
stloc.0 <null>
nop <null>
ldstr An unexpected error occurred: {0}

The application will now close.
ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
call System.String System.String::Format(System.String,System.Object)
ldstr Fatal Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0040: ret
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNetworkAnalyzer.Forms.MainForm.resources
SmartNetworkAnalyzer.Properties.Resources.resources
greyder
[NBF]root.Data
uOA
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙