Suspicious
Suspect

PE Executable
MD5: 19749cbbe630307819e3b809a92f15aa
Size: 1.19 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 19749cbbe630307819e3b809a92f15aa
Sha1 ae0f22032531c8f0229ba831ddba32cbe9a1d02a
Sha256 9b372aa138671e6ea5c0be48db655a7f62172d9affe4d28c0559b28bf5181a67
Sha384 842c7b013c6688942fa3225a1a07d44a618d15af8c71ab9ba02976e177965a6e5efe1125a0465231ec9926856b1f0067
Sha512 9c35e8296be1b08a02e3d8bdf485e3f4f434ba89c5b8261ffe4a8cf68c4fd8e55a664f81a710a1d4a5e2b1b9c4f7ffb3d22a2e684bec1944bafb71a333d277b2
SSDeep 24576:XSnA9hjSVhAezVMGwUuTzhCFGotQJeHQFvlvtcbHqSO3CbCwtRNRnJx0wUmr9XEv:J/SYMGUuqGoWJouvOqd6vvTnJOw9r9c
TLSH 4B4522B05328DB27E5E207B04975E3B927B81EDCB120E31A5EE93CEB7C2671065507A7
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RESTAURANT_ORDER_SYSTEM.frm_restaurant.resources
$this.Icon
[NBF]root.IconData
gap
[NBF]root.Data
menuStrip1.TrayLocation
RESTAURANT_ORDER_SYSTEM.FrmNewProduct.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
RESTAURANT_ORDER_SYSTEM.FrmNewTable.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
RESTAURANT_ORDER_SYSTEM.FrmUpdatePrice.resources
RESTAURANT_ORDER_SYSTEM.Properties.Resources.resources
YWSr
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\JXsoZXIoHC\src\obj\Debug\wfJB.pdb
Module Name
wfJB.exe
Full Name
wfJB.exe
EntryPoint
System.Void RESTAURANT_ORDER_SYSTEM.Program::Main()
Scope Name
wfJB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wfJB
Assembly Version
4.6.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
231
Main Method
System.Void RESTAURANT_ORDER_SYSTEM.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RESTAURANT_ORDER_SYSTEM.frm_restaurant::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RESTAURANT_ORDER_SYSTEM.frm_restaurant.resources
$this.Icon
[NBF]root.IconData
gap
[NBF]root.Data
menuStrip1.TrayLocation
RESTAURANT_ORDER_SYSTEM.FrmNewProduct.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
RESTAURANT_ORDER_SYSTEM.FrmNewTable.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
RESTAURANT_ORDER_SYSTEM.FrmUpdatePrice.resources
RESTAURANT_ORDER_SYSTEM.Properties.Resources.resources
YWSr
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙