Suspicious
Suspect

PE Executable
MD5: 19eb32882087f209dfe2b598e9f7123d
Size: 716.29 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 19eb32882087f209dfe2b598e9f7123d
Sha1 ce2e8b77cc5661a2d7398f847bebbc3baa05d934
Sha256 446ac5b2673ba02db508a71c3c821a4f5b2f6d9b0f8e4af62a7b747dceae33a9
Sha384 e6587d6588d3d82deaa79aa59cbc93583708a465c27d452c75ac066e3854cf52f83ee1648d79fd4d09f2a64c06e05393
Sha512 8c1d7f8364fe3b7810aeb05d11c64aa628a0daae872a71f30e95368602a60dab886aa3aa1e609fffd18bf1949646c661bf359ec8d3dce52faf3197b67ded888c
SSDeep 12288:ErKIJoo+fbe2bcYeAacDGadsA2FE1s912WrHlq7135d+hF50IQa9doBLbOIb:+K8oouy+2IGaGsY/rHlq79O+Ir9CBLbL
TLSH DCE41241B795C962D5F907F01A21D3B35779AECD6814C20FC8EEFCEBB91A3843855292
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PerformanceObjects.Properties.Resources.resources
SDZq
cls
Name Value
Module Name
PJDf.exe
Full Name
PJDf.exe
EntryPoint
System.Void PerformanceObjects.Program::Main()
Scope Name
PJDf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PJDf
Assembly Version
1.6.1808.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
230
Main Method
System.Void PerformanceObjects.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PerformanceObjects.StrategicForm16::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
PJDf.exe
Full Name
PJDf.exe
EntryPoint
System.Void PerformanceObjects.Program::Main()
Scope Name
PJDf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PJDf
Assembly Version
1.6.1808.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
230
Main Method
System.Void PerformanceObjects.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PerformanceObjects.StrategicForm16::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PerformanceObjects.Properties.Resources.resources
SDZq
cls
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
19eb32882087f209dfe2b598e9f7123d
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
19eb32882087f209dfe2b598e9f7123d
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙