Suspicious
Suspect

099b82e9dfc2d96674e1a440c755393f

PE Executable
MD5: 099b82e9dfc2d96674e1a440c755393f
Size: 834.56 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 099b82e9dfc2d96674e1a440c755393f
Sha1 b910edbfcdbc2d6c4a0f5241e0e518a9537ff4bb
Sha256 d89a76737ea433332fec51bc5662a0c87ed094e8dd6fcd9dd484377cc2ec5d88
Sha384 cbd09112f5ec080cb3a6e03ccba22505153432c8711121cd2a0ffff5c75683446fad9e18b04ffac5173f6be5ca7153d9
Sha512 1cb6286f1ad04348bd9566d13ad27f4624c9925cd55c2a1d5373245d6f4bee5cd61028ca0274f5b446c61dc358386f1dcd08d2ae8cfad3b7d14164c65d52168b
SSDeep 12288:6znnf4i78C72VaZ2F4tfrKmCebMyBdm0ZGBerujpfpQPY4BUjVOhizP+GQGaZu07:gnnf4iWpCtfOmFBU0OEujpf/dugRo9
TLSH E20501813212DA03D4551BF0596EE7FC62781E9BB930EE42FEE47CCB7839728654A253
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator_Project.Calculator.resources
$this.Icon
[NBF]root.IconData
greyder
[NBF]root.Data
Login_And_Register_Form.registerForm.resources
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Login_And_Register_Form.frmLogin.resources
Login_And_Register_Form.Properties.Resources.resources
kWL
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
jLY.exe
Full Name
jLY.exe
EntryPoint
System.Void Login_And_Register_Form.Program::Main()
Scope Name
jLY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jLY
Assembly Version
6.3.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
174
Main Method
System.Void Login_And_Register_Form.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Login_And_Register_Form.registerForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
jLhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Calculator_Project.Calculator.resources
$this.Icon
[NBF]root.IconData
greyder
[NBF]root.Data
Login_And_Register_Form.registerForm.resources
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
pictureBox2.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Login_And_Register_Form.frmLogin.resources
Login_And_Register_Form.Properties.Resources.resources
kWL
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
jLhuhuhuhu
099b82e9dfc2d96674e1a440c755393f
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙