Suspicious
Suspect

PE Executable
MD5: 1e41f8dd9683d21f88c047afca3392e1
Size: 924.16 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 1e41f8dd9683d21f88c047afca3392e1
Sha1 f40b12051901cad222ecfd1215cc1efa8b171fc2
Sha256 0ca4e2896859ee2bbd20d1cb46efc20b0f2c67aa58d7391579660698789aa855
Sha384 66b8a72b2b85b116eb6ea5559f415c5da9a5762a78afe85ebee8e99361ee92d712401f5c3904dc2d0922324d47deef86
Sha512 48b0d6f029cc0b92fa550794b1ec6615d765503a0412319d9d7537e7d1d991e9a4748103f0fa828ec5308ce399427ab05ae3d9c1bec0c86903b69e42146f6cfd
SSDeep 24576:HPbi4NqCyNlEys5E2XvKreRHpif9K++Yrt:HfNR3rOBxf9F
TLSH C515129462A5D602E8B19BF81A32E2700B787EDF7911D31F5FE9BCDB34A2B154C14263
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NetworkManager.FormActiverDesactiver.resources
NetworkManager.Properties.Resources.resources
gr
[NBF]root.Data
iEKHH
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: HjZzw.pdb
Module Name
HjZzw.exe
Full Name
HjZzw.exe
EntryPoint
System.Void NetworkManager.Program::Main()
Scope Name
HjZzw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
HjZzw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
417
Main Method
System.Void NetworkManager.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NetworkManager.FormListeAdaptateurs::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
HjZzw.exe
Full Name
HjZzw.exe
EntryPoint
System.Void NetworkManager.Program::Main()
Scope Name
HjZzw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
HjZzw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
417
Main Method
System.Void NetworkManager.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NetworkManager.FormListeAdaptateurs::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NetworkManager.FormActiverDesactiver.resources
NetworkManager.Properties.Resources.resources
gr
[NBF]root.Data
iEKHH
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙