Suspicious
Suspect

PE Executable
MD5: 2328350ba2eb886a9d9b6ed9ff2e8772
Size: 778.24 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2328350ba2eb886a9d9b6ed9ff2e8772
Sha1 51473abb5c5e8d7c99f0bc75266db04eb1cf1c4d
Sha256 9e896f9419ea6acaffb5770d2ad2922fc4880b52e1ebfe561603e281f942fe62
Sha384 1825a8a163105eb24c182d2bb55f2c01e48c1a6f918975664e3ad817f06ac3e8ab522d6a8c25dd360419b7cf0fe4987b
Sha512 21c5916b7cdf7c91ddb15a51a253f0e2bb208c8d67811b90d6d7d6519c6c2eb7bcefdd7050342923b00623a0b8868cd1018b2c766eaa1a70430bbceffcd30c7f
SSDeep 12288:45iPx7untvfhIPQvZ6wUU7mUoud2zSwZARwSuYu5DE46tkAsbJqbfXdwtaN6WIsO:45iZ7wpfyIvZVf7loud23C2Yu5IvtrS9
TLSH 03F40255239AEF02D5A11BF40970E3B40378BD99A821C30B4EFBACDFB87935065653A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CSS_Minifier.Forms.MainForm.resources
CSS_Minifier.Properties.Resources.resources
crt
[NBF]root.Data
jzvD
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: yTvL.pdb
Module Name
yTvL.exe
Full Name
yTvL.exe
EntryPoint
System.Void CSS_Minifier.Program::Main()
Scope Name
yTvL.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yTvL
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
385
Main Method
System.Void CSS_Minifier.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CSS_Minifier.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
yTvL.exe
Full Name
yTvL.exe
EntryPoint
System.Void CSS_Minifier.Program::Main()
Scope Name
yTvL.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yTvL
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
385
Main Method
System.Void CSS_Minifier.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CSS_Minifier.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CSS_Minifier.Forms.MainForm.resources
CSS_Minifier.Properties.Resources.resources
crt
[NBF]root.Data
jzvD
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙