Suspicious
Suspect

PE Executable
MD5: 25e817c84770298f920f28c3a949ee9e
Size: 1.06 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 25e817c84770298f920f28c3a949ee9e
Sha1 b6051b726f317fa370285ae51c275dd7e8987dc4
Sha256 8be521d630b1c7285e4e2074443ba82175636714302b975bd27da3e0cb6fc270
Sha384 044a5e8f800a85289c2a286eb10d1578a8e7226a39510d17f7bb9a2c7a3344df981e6686e7fcd3bdfafd2d57566bdad0
Sha512 d166f721440d19d090feab831cdd0e35b7054240c4a7cc43f03ef03e61ad06bfc197c9c3897099cd088cf021d59240cc8130f51ff833b222ccdb288b180d20c7
SSDeep 24576:UFkJsY6nwU6xn365vg0BrfSOY/Apekrx5OdLwt5L3lkc:FaYbJgzSjAkkrxQxkB3lJ
TLSH E125F1882626DA21CDA9C7F04720DEF223B07E6B9414D3160DD5FCEB7D627691CD86A3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
ELLu.exe
Full Name
ELLu.exe
EntryPoint
System.Void ModernAdapter.Program::Main()
Scope Name
ELLu.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ELLu
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
617
Main Method
System.Void ModernAdapter.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void ModernAdapter.Program::InitializeApplication()
nop <null>
newobj System.Void ModernAdapter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ELLu.exe
Full Name
ELLu.exe
EntryPoint
System.Void ModernAdapter.Program::Main()
Scope Name
ELLu.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ELLu
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
617
Main Method
System.Void ModernAdapter.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void ModernAdapter.Program::InitializeApplication()
nop <null>
newobj System.Void ModernAdapter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
25e817c84770298f920f28c3a949ee9e
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
25e817c84770298f920f28c3a949ee9e
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙