Suspicious
Suspect

PE Executable
MD5: ffd54474c6b7e5f69684d2257de7db31
Size: 1.09 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 ffd54474c6b7e5f69684d2257de7db31
Sha1 9b1ea31b6530d2f12e22e5816074453e3f410848
Sha256 16ff90b14867d9cde7cf8d405da63ea0c87f2c0cada7f00224d0099cb1a27d65
Sha384 d6edfdd571e9879e87000b5234b77efd6f39b63dacfdb6f00241d7aa1384bd045362ed6374319e83ffcabcca11b5a17d
Sha512 a91daa2987817ea2b13c618b98ee7b9061bca6261c5d126e3d25037ffd0bdf8cff402864bbf9fe6c124af02020444cdfdb02dad2b3a23fb245fe17836b25543b
SSDeep 24576:yZqu2VaZatdrM6LgeXRN83hm8HTuBoGiwQ7CFvXJh5Fcb:yeVa3XXB6+2Q7MXV
TLSH AF351255372ADC03D4A24EF11972D3F46BB86E9C9811E383CEEA7DDBB579A442C40293
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AdvancedMdiExample.AboutBoxForm.resources
$this.Icon
[NBF]root.IconData
ShutdownTimers.MainForm.resources
AF
[NBF]root.Data
mainTimer.TrayLocation
sysTrayContextMenu.TrayLocation
systemTray.TrayLocation
ShutdownTimers.Form2.resources
ShutdownTimers.Properties.Resources.resources
iZBZ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
bUIY.exe
Full Name
bUIY.exe
EntryPoint
System.Void ShutdownTimers.Program::Main()
Scope Name
bUIY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bUIY
Assembly Version
11.8.4.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
222
Main Method
System.Void ShutdownTimers.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void ShutdownTimers.Form3::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
bUIY.exe
Full Name
bUIY.exe
EntryPoint
System.Void ShutdownTimers.Program::Main()
Scope Name
bUIY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bUIY
Assembly Version
11.8.4.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
222
Main Method
System.Void ShutdownTimers.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void ShutdownTimers.Form3::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AdvancedMdiExample.AboutBoxForm.resources
$this.Icon
[NBF]root.IconData
ShutdownTimers.MainForm.resources
AF
[NBF]root.Data
mainTimer.TrayLocation
sysTrayContextMenu.TrayLocation
systemTray.TrayLocation
ShutdownTimers.Form2.resources
ShutdownTimers.Properties.Resources.resources
iZBZ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙