Suspicious
Suspect

2eada8ddecb2f9e83d1d474bf24655f7

PE Executable
MD5: 2eada8ddecb2f9e83d1d474bf24655f7
Size: 1.1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 2eada8ddecb2f9e83d1d474bf24655f7
Sha1 86dfdf175d4c16b0c91cfda903df0f8297d4dfa4
Sha256 e3ab15a37eb0ac7fc858be0a57d6ca34de07545ec156cab774114a031c72ab4e
Sha384 1ce500115785913849ece046593577b07ddad708ce2b78f8d12921749bfc81ebc935c6d93a6df720b473b4da3566d943
Sha512 9008f75f3b52797854da19d47d09ec92c6c915a4e9e02533b69ef92616c9c69987a9d8fd76d57f4aeab5c64302ee4fa26d630701c8a0b2814be52aa2d2e177be
SSDeep 24576:vxVb6zMlSaXYJ4puII1xR2PYOLc9CkXasx:vxl6zMlSlJMI1xR2PWd
TLSH 003512A523D4EA03EAFF96F891B0C23557B66D5A7112D3CB9CD45CEB74F2B102912283
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
StormCast.StrategicForm33.resources
$this.Icon
vgx
StormCast.Properties.Resources.resources
rYXH
Name Value
Module Name
KxJr.exe
Full Name
KxJr.exe
EntryPoint
System.Void StormCast.Program::Main()
Scope Name
KxJr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KxJr
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1037
Main Method
System.Void StormCast.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void StormCast.StrategicForm33::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
KxJr.exe
Full Name
KxJr.exe
EntryPoint
System.Void StormCast.Program::Main()
Scope Name
KxJr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KxJr
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1037
Main Method
System.Void StormCast.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void StormCast.StrategicForm33::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
StormCast.StrategicForm33.resources
$this.Icon
vgx
StormCast.Properties.Resources.resources
rYXH
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
2eada8ddecb2f9e83d1d474bf24655f7
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
2eada8ddecb2f9e83d1d474bf24655f7
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙