Suspicious
Suspect

PE Executable
MD5: 19f77f8c6592a72ccb901076306b45d2
Size: 1.48 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 19f77f8c6592a72ccb901076306b45d2
Sha1 098758dcbcb7dffda5ac07d7fb74bb2ac781b3c4
Sha256 01f70dc5175c6daae296b4dbba49897b1fb6e5a294f26b045a6debf7b49faa11
Sha384 dfae70096a22d6b7ef7213e6ba2ed32a6296e7bb681e221586be7c4629a3eb3ffb8f9a3297be235c3bd9a19bc7bba767
Sha512 4d62ba5df9d0eba707a79c5afcd558d68e9a77f1e6bb436a66229dee6b861799ea9eaa321fb2550c11f0e2e96f314e6f2e175845c36e3d6f17449bd69e2d4f0c
SSDeep 24576:2vFSJJSHwmuA9O3sWkZfFRQJR1PbCGcZ0YSJvXO/LbrNueFZF9npMK:6qUwmuA9OcZfglTCGcZ0YSvO/LNu+ZFZ
TLSH DF65010467ABDC02D4BA1BB588F0D37407F8AD51E422C2076FE67DDFBA267922985353
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
jK.oD.resources
Unv.In5.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RhythmTracker.Properties.Resources.resources
finn
[NBF]root.Data
ieLz
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
hjVq.exe
Full Name
hjVq.exe
EntryPoint
System.Void s9.Xc::JI()
Scope Name
hjVq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hjVq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
576
Main Method
System.Void s9.Xc::JI()
Main IL Instruction Count
16
Main IL
br IL_0007: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002C: nop
nop <null>
newobj System.Void jK.oD::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0005: nop
call System.Void F4g.t4d::F5K()
br IL_0012: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0022: call System.Void F4g.t4d::F5K()
Module Name
hjVq.exe
Full Name
hjVq.exe
EntryPoint
System.Void s9.Xc::JI()
Scope Name
hjVq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hjVq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
576
Main Method
System.Void s9.Xc::JI()
Main IL Instruction Count
16
Main IL
br IL_0007: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002C: nop
nop <null>
newobj System.Void jK.oD::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0005: nop
call System.Void F4g.t4d::F5K()
br IL_0012: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0022: call System.Void F4g.t4d::F5K()
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
jK.oD.resources
Unv.In5.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RhythmTracker.Properties.Resources.resources
finn
[NBF]root.Data
ieLz
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙