Suspicious
Suspect

PE Executable
MD5: 284307bded378e896c5e435abe772c26
Size: 714.24 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 284307bded378e896c5e435abe772c26
Sha1 265218f671ee2be93fa03a465ed6888f44b37c4b
Sha256 36a075c198f7bd34a5a7ac2981d644428a32d32efdcb6f5a16ce1b085f0fc08e
Sha384 671e605a39ed9f96b75a477e77f7a31e59b1ef82406823e9ea3bfb8cfbc42526faf27b542f97fdd46ada3bbef85d6ba6
Sha512 e5144133f389c89d3a57770d8377eb37299d783114cd27bc380ebae63997b10dfc73bc7b220c7222ff380cf82b8033cd87863e980fc5a66e4aa54dbd291acafe
SSDeep 12288:ZgGI2d++PR1HgAr3Qsya7G+Dq2vcGyK9S205r3f2gFmhpfm/3plP:ZguICR1AADQslDq20VK0r3hF+45lP
TLSH 1DE402083667DB26C8B647FA1932E27023756E49B911DB0E9FD62DDF7C62B021B02347
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HTA_pharmacy.Form1.resources
HTA_pharmacy.Form3.resources
$this.AutoScaleDimensions
$this.ClientSize
$this.Margin
button1.Font
button1.Location
button1.Size
button2.Font
button2.Location
button3.Location
button3.Size
button4.Location
button4.Size
button5.Location
button6.Location
dataGridView1.Location
dataGridView1.Size
dateTimePicker1.Location
dateTimePicker1.Size
label1.Location
label1.Size
label3.Location
label3.Size
label4.Location
label4.Size
textBox1.Location
textBox1.Size
textBox2.Location
HTA_pharmacy.Properties.Resources.resources
BxXm
[NBF]root.Data
[NBF]root.Data-preview.png
MR
[NBF]root.Data
Name Value
Module Name
nJYp.exe
Full Name
nJYp.exe
EntryPoint
System.Void HTA_pharmacy.Program::Main()
Scope Name
nJYp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nJYp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
351
Main Method
System.Void HTA_pharmacy.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HTA_pharmacy.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
nJYp.exe
Full Name
nJYp.exe
EntryPoint
System.Void HTA_pharmacy.Program::Main()
Scope Name
nJYp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nJYp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
351
Main Method
System.Void HTA_pharmacy.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HTA_pharmacy.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
nJhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HTA_pharmacy.Form1.resources
HTA_pharmacy.Form3.resources
$this.AutoScaleDimensions
$this.ClientSize
$this.Margin
button1.Font
button1.Location
button1.Size
button2.Font
button2.Location
button3.Location
button3.Size
button4.Location
button4.Size
button5.Location
button6.Location
dataGridView1.Location
dataGridView1.Size
dateTimePicker1.Location
dateTimePicker1.Size
label1.Location
label1.Size
label3.Location
label3.Size
label4.Location
label4.Size
textBox1.Location
textBox1.Size
textBox2.Location
HTA_pharmacy.Properties.Resources.resources
BxXm
[NBF]root.Data
[NBF]root.Data-preview.png
MR
[NBF]root.Data
No malware configuration was found at this point.
PDB Path PATH
nJhuhuhuhu
284307bded378e896c5e435abe772c26
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙