Suspicious
Suspect

PE Executable
MD5: 10a1c5245f2f0d8eeea1e553003912c4
Size: 584.7 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 10a1c5245f2f0d8eeea1e553003912c4
Sha1 a680d711677b156f4377a985b1f0df9b06472c20
Sha256 800b2d20d87be38e59ed0836a71820ff042a39c3087cfcaa26bd20d1e0db78d4
Sha384 2cc9bea8d84ae39a6901524b1770c2142813aa0e3b4e6ebbd9a044b8e7a82080139ec063e5bda0a469d44a48f288a66a
Sha512 5bb3409fc30c852f6046bff176cd44dacea89db754ae8564ceffd603de3ca488ecdafe9cd531988b58532194cfbf2ddf0e4eaa435224a7abedf5b403eb5beca6
SSDeep 12288:ojbsKZaywhhFuKbMlOQoqMhrSwVRNf/F4lx5jQT:ojbsKwyEhFu/VchVfN3aG
TLSH 3AC4F14195938D07E5A70BBC2BAAC1351A325FDFA42AC70F9EC63DE7B5733855281B02
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETPrivate EXE Protector V2.30-V2.3X -> SetiSoft Team
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsApp51.StudentInfoForm.resources
WindowsFormsApp51.StudentsManagerForm.resources
$this.Icon
xsh
WindowsFormsApp51.Properties.Resources.resources
JaJo
Database.StudentsManagerModel.csdl
Database.StudentsManagerModel.msl
Database.StudentsManagerModel.ssdl
Name Value
Module Name
ojWA.exe
Full Name
ojWA.exe
EntryPoint
System.Void WindowsFormsApp51.Program::Main()
Scope Name
ojWA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ojWA
Assembly Version
5.6.14.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
218
Main Method
System.Void WindowsFormsApp51.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WindowsFormsApp51.StudentsManagerForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ojWA.exe
Full Name
ojWA.exe
EntryPoint
System.Void WindowsFormsApp51.Program::Main()
Scope Name
ojWA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ojWA
Assembly Version
5.6.14.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
218
Main Method
System.Void WindowsFormsApp51.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WindowsFormsApp51.StudentsManagerForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
ojhuhuhuhu
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsApp51.StudentInfoForm.resources
WindowsFormsApp51.StudentsManagerForm.resources
$this.Icon
xsh
WindowsFormsApp51.Properties.Resources.resources
JaJo
Database.StudentsManagerModel.csdl
Database.StudentsManagerModel.msl
Database.StudentsManagerModel.ssdl
No malware configuration was found at this point.
PDB Path PATH
ojhuhuhuhu
10a1c5245f2f0d8eeea1e553003912c4
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
10a1c5245f2f0d8eeea1e553003912c4
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
10a1c5245f2f0d8eeea1e553003912c4
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙