Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 2e2878bc7366a60aa27de72876320ae2
Size: 720.38 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 2e2878bc7366a60aa27de72876320ae2
Sha1 699d801c69c6f18fed995f666f697ed5d36b3d42
Sha256 19a8d3ab5729bbdca1fbf108aa0ccda5a7245860ca14b76b72e6314faa69e134
Sha384 390883034fee1dbbedd43ec5e3b6adcdcc0710d17a7c24889f843db57c4c2f36d933691a651c45ea22a7023dff7a6b9d
Sha512 db9ba09a1eafc8e8b5daeee5d9b1ddb15605a040386d8ee9af8a224c2df07009653165811b26a02a746d2c3b26673ccfb0a3baa6969fc0ab420bac6b76bd4e90
SSDeep 12288:k2EMLQw8Qjm89wKurISXY12WayDN1OsJIQeItlm9tGpouolbn3XEhAFtKdD:k2EMLN8QjqKuk8Y+yDDOQemmHGp4p3XQ
TLSH EBE4016076A9EB25C9B983F51371E37513B46ECDA422E30A4ED5BCFB3625B012D61383
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Medical_Store.Bill.resources
Medical_Store.Properties.Resources.resources
IKqr
chb
Name Value
Module Name
sKDj.exe
Full Name
sKDj.exe
EntryPoint
System.Void Medical_Store.Program::Main()
Scope Name
sKDj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sKDj
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
354
Main Method
System.Void Medical_Store.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Medical_Store.Login::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
sKDj.exe
Full Name
sKDj.exe
EntryPoint
System.Void Medical_Store.Program::Main()
Scope Name
sKDj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sKDj
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
354
Main Method
System.Void Medical_Store.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Medical_Store.Login::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙