Suspicious
Suspect

PE Executable
MD5: 07ce23e7821ed76230655cff55ee5af3
Size: 742.4 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 07ce23e7821ed76230655cff55ee5af3
Sha1 1b03b2879aae22c6a65c473320ff2db1bca0a271
Sha256 49ef1d66eb97245c704e2e92e369ae6b9d5dd5319376b136dbdb297196a472af
Sha384 82cadf05e4cefcf75170f3bafa3936903095ad2671f3a56b440b8260d8fc32c1102e160ecac53fc6f3f4d8f18eda768d
Sha512 de5abb5e68ba7276c4bd010066cca1a04306180f7740a2569caa721cdf02000fca34593d186eb9346b8d22853b57e3479d78e63ca3f33721e3d1d22e3ea51de7
SSDeep 12288:T/pppppppppjHpppppppppp3j3S2SGF9RJUahWNjibTv8MIdDmfU+tfD9C/GVIAB:T/pppppppppjHpppppppppp3j3iGF9Rz
TLSH 19F412293196ED22FC851BB400B2D7B103750FDCA422D30A9ADD7CE77A7BB1A7458786
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
usercontrolwithdatabinding.Form1.resources
$this.Icon
[NBF]root.IconData
bsCustomer.TrayLocation
engh
[NBF]root.Data
errorProvider1.TrayLocation
usercontrolwithdatabinding.Properties.Resources.resources
LRDx
[NBF]root.Data
[NBF]root.Data-preview.png
usercontrolwithdatabinding.UserControls.AddressControl.resources
Name Value
Module Name
JkSF.exe
Full Name
JkSF.exe
EntryPoint
System.Void usercontrolwithdatabinding.Program::Main()
Scope Name
JkSF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JkSF
Assembly Version
1.2.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
106
Main Method
System.Void usercontrolwithdatabinding.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void usercontrolwithdatabinding.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
usercontrolwithdatabinding.Form1.resources
$this.Icon
[NBF]root.IconData
bsCustomer.TrayLocation
engh
[NBF]root.Data
errorProvider1.TrayLocation
usercontrolwithdatabinding.Properties.Resources.resources
LRDx
[NBF]root.Data
[NBF]root.Data-preview.png
usercontrolwithdatabinding.UserControls.AddressControl.resources
No malware configuration was found at this point.
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
07ce23e7821ed76230655cff55ee5af3
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙