Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 1cb8e15c757aa396c9bf7b2ca7c932ff
Size: 898.56 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 1cb8e15c757aa396c9bf7b2ca7c932ff
Sha1 7fc623f819d167e4f490629d26db1bcd411e1aed
Sha256 9af23a04d5aaa31d148764d642922392d5d5dcb845fa1a4728afcd81cf46a87f
Sha384 5ab9a01c7d14b58071aa895a5b187b35361820ed247b6d02a3828196c355bcd287ac5f6a176448f87adcf306fcb39b33
Sha512 860dc36c2bacfcdcb3361bd212fbafbf5245d6c416a284d8dd0ea190dfbeadacfde37f6de663dff6a8736c68cd40fac9d8c4121905780db2a637a59aabd066e3
SSDeep 24576:vQ814hXqSF9fjK7o04R2T6jqLri5UKlOJ:N2haSXjEo04R2WmkpOJ
TLSH 8115DFB1F2B58855D49867714926D83021E72DFCECA1D30AD6DA7CAB79B3FC2085290F
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Zapsinaya_knizka_new.Form01.resources
$this.Icon
[NBF]root.IconData
Zapsinaya_knizka_new.Form1.resources
$this.Icon
[NBF]root.IconData
Zapsinaya_knizka_new.Properties.Resources.resources
de
[NBF]root.Data
siTe
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
eLLJ.exe
Full Name
eLLJ.exe
EntryPoint
System.Void Zapsinaya_knizka_new.Program::Main()
Scope Name
eLLJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
eLLJ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
217
Main Method
System.Void Zapsinaya_knizka_new.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Zapsinaya_knizka_new.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
eLLJ.exe
Full Name
eLLJ.exe
EntryPoint
System.Void Zapsinaya_knizka_new.Program::Main()
Scope Name
eLLJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
eLLJ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
217
Main Method
System.Void Zapsinaya_knizka_new.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Zapsinaya_knizka_new.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙