Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 2328350ba2eb886a9d9b6ed9ff2e8772
Size: 778.24 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2328350ba2eb886a9d9b6ed9ff2e8772
Sha1 51473abb5c5e8d7c99f0bc75266db04eb1cf1c4d
Sha256 9e896f9419ea6acaffb5770d2ad2922fc4880b52e1ebfe561603e281f942fe62
Sha384 1825a8a163105eb24c182d2bb55f2c01e48c1a6f918975664e3ad817f06ac3e8ab522d6a8c25dd360419b7cf0fe4987b
Sha512 21c5916b7cdf7c91ddb15a51a253f0e2bb208c8d67811b90d6d7d6519c6c2eb7bcefdd7050342923b00623a0b8868cd1018b2c766eaa1a70430bbceffcd30c7f
SSDeep 12288:45iPx7untvfhIPQvZ6wUU7mUoud2zSwZARwSuYu5DE46tkAsbJqbfXdwtaN6WIsO:45iZ7wpfyIvZVf7loud23C2Yu5IvtrS9
TLSH 03F40255239AEF02D5A11BF40970E3B40378BD99A821C30B4EFBACDFB87935065653A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CSS_Minifier.Forms.MainForm.resources
CSS_Minifier.Properties.Resources.resources
crt
[NBF]root.Data
jzvD
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: yTvL.pdb
Module Name
yTvL.exe
Full Name
yTvL.exe
EntryPoint
System.Void CSS_Minifier.Program::Main()
Scope Name
yTvL.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yTvL
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
385
Main Method
System.Void CSS_Minifier.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CSS_Minifier.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
yTvL.exe
Full Name
yTvL.exe
EntryPoint
System.Void CSS_Minifier.Program::Main()
Scope Name
yTvL.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yTvL
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
385
Main Method
System.Void CSS_Minifier.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CSS_Minifier.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙