Suspicious
Suspect

PE Executable
MD5: 2e2878bc7366a60aa27de72876320ae2
Size: 720.38 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 2e2878bc7366a60aa27de72876320ae2
Sha1 699d801c69c6f18fed995f666f697ed5d36b3d42
Sha256 19a8d3ab5729bbdca1fbf108aa0ccda5a7245860ca14b76b72e6314faa69e134
Sha384 390883034fee1dbbedd43ec5e3b6adcdcc0710d17a7c24889f843db57c4c2f36d933691a651c45ea22a7023dff7a6b9d
Sha512 db9ba09a1eafc8e8b5daeee5d9b1ddb15605a040386d8ee9af8a224c2df07009653165811b26a02a746d2c3b26673ccfb0a3baa6969fc0ab420bac6b76bd4e90
SSDeep 12288:k2EMLQw8Qjm89wKurISXY12WayDN1OsJIQeItlm9tGpouolbn3XEhAFtKdD:k2EMLN8QjqKuk8Y+yDDOQemmHGp4p3XQ
TLSH EBE4016076A9EB25C9B983F51371E37513B46ECDA422E30A4ED5BCFB3625B012D61383
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Medical_Store.Bill.resources
Medical_Store.Properties.Resources.resources
IKqr
chb
Name Value
Module Name
sKDj.exe
Full Name
sKDj.exe
EntryPoint
System.Void Medical_Store.Program::Main()
Scope Name
sKDj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sKDj
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
354
Main Method
System.Void Medical_Store.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Medical_Store.Login::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
sKDj.exe
Full Name
sKDj.exe
EntryPoint
System.Void Medical_Store.Program::Main()
Scope Name
sKDj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sKDj
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
354
Main Method
System.Void Medical_Store.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Medical_Store.Login::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Medical_Store.Bill.resources
Medical_Store.Properties.Resources.resources
IKqr
chb
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
2e2878bc7366a60aa27de72876320ae2
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
2e2878bc7366a60aa27de72876320ae2
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙