Suspicious
Suspect

PE Executable
MD5: 02c481939b56454dcab0b1b21c9d3fa1
Size: 1.21 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 02c481939b56454dcab0b1b21c9d3fa1
Sha1 817fb152eff621436e4fb3678bc460918c05ba36
Sha256 14f8ff92c7bc84e9d50fc0c7d6df09642d10fb928c2edb20953c9aa8fd3e5dc8
Sha384 815eeee1fb92868e1b430ceccfd630c635d311c9f5565ecda0e47efaf64b339f54feed30a9fa99f059fe8d3d0108b37e
Sha512 32d15b259e83984cb9a517c84901d7a35ea9ee4e1472546cc53c6c730cbe2b202791c2c889dfcce7abee137f29be549433679e542b8a0fdae9b5dd053668e560
SSDeep 24576:CaYYhtvAuipR+Qvq5GwE3Qrj5jsjGCf2tthEloTs:oKtY7VylE3SdQGCf2ttx
TLSH 0C4523A9355EDE13CAB60BF419B0E03187B45E9E9801C30B4BEE6CDF7435B0669896D3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpeedType.FormMenuPrincipal.resources
SpeedType.Properties.Resources.resources
Fast_Tot
[NBF]root.Data
[NBF]root.Data-preview.png
JsTt
[NBF]root.Data
[NBF]root.Data-preview.png
oO
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: HyHu.pdb
Module Name
HyHu.exe
Full Name
HyHu.exe
EntryPoint
System.Void SpeedType.Program::Main()
Scope Name
HyHu.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
HyHu
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
299
Main Method
System.Void SpeedType.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpeedType.FormMenuPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
HyHu.exe
Full Name
HyHu.exe
EntryPoint
System.Void SpeedType.Program::Main()
Scope Name
HyHu.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
HyHu
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
299
Main Method
System.Void SpeedType.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpeedType.FormMenuPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpeedType.FormMenuPrincipal.resources
SpeedType.Properties.Resources.resources
Fast_Tot
[NBF]root.Data
[NBF]root.Data-preview.png
JsTt
[NBF]root.Data
[NBF]root.Data-preview.png
oO
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙