Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 2d58013036d2af43f1170a4e3ab0f9e8
Size: 739.33 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 2d58013036d2af43f1170a4e3ab0f9e8
Sha1 f2f1979471fa13a555637bbea00caeebf87025e7
Sha256 55fdadeea5fe30020da4f590673348e809b2a736b5721bc4611be074288e62aa
Sha384 105d12d77ff558ef30c4ceef6add592b9920a0a4fd4df58c05d0a25d9f5d898300cbe5db69644abf2348775a214531e9
Sha512 72cc543eff1213b2e6ac0e187cc006cfe40a2ce0657a2b935ace4f242e0c4ef2ee0ef5b6fc6d1481973440fd2d7d287608aaf60f1f7d6c82015b91d348d1e704
SSDeep 12288:cm0xh0Rk1FO6dQe5DZpMJOUzd5NoesRf70jix1LkEdSmVAnEekV1JnB+JAGaemH0:dw7TeOUzfKJx7SixFkYZVAwBEEDHRqWU
TLSH 6FF402042BDDD625E1B95BB51932E3784BBC7D8AAD20E24A5BC96CEF3D39B408C10753
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MonitorSync.Properties.Resources.resources
HQ
[NBF]root.Data
uNQq
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
iyui.exe
Full Name
iyui.exe
EntryPoint
System.Void MonitorSync.Program::Main()
Scope Name
iyui.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iyui
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
491
Main Method
System.Void MonitorSync.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MonitorSync.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
iyhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙