Suspicious
Suspect

PE Executable
MD5: 31aef6d32669bc5807b348f948bcc2ad
Size: 695.81 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 31aef6d32669bc5807b348f948bcc2ad
Sha1 1bb9861dc6f0041c33972e7a407f3c70e0748838
Sha256 5756e25b85cd80cc50822ff08493723729b4f99d37d2a0e26a4a0fa244c7db15
Sha384 74075422fe963bc8ba2ba3280c768d36491f4bd95982b25e83e46e8cbc93f95bd8978aee70a95bc614e70541d02f37b5
Sha512 087058e39f0de10e671341cbb1eaf7ba2d67d455a8049339164c0a9f9dab9c6c2df480502bcea15740496267e6012bc3cb92012673f9579e85f61c39d47afecf
SSDeep 12288:A7Ts8VyPDhi87TL1nBX9AsmnKl/0KnTZrBDKa3FGW1U5nFU2Bo8Bc6:6jVyPDhi87TJBCnKl1Tp/3F71qUCox6
TLSH 27E41214322CCA17C4A25BF16972C1B817647ECEEC60D247DFC9BEDFB4B96189857282
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SystemDashboard.MainForm.resources
SystemDashboard.Properties.Resources.resources
FRcby
[NBF]root.Data
[NBF]root.Data-preview.png
LayerT
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: FjEAI.pdb
Module Name
FjEAI.exe
Full Name
FjEAI.exe
EntryPoint
System.Void SystemDashboard.Program::Main()
Scope Name
FjEAI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FjEAI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
184
Main Method
System.Void SystemDashboard.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SystemDashboard.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
FjEAI.exe
Full Name
FjEAI.exe
EntryPoint
System.Void SystemDashboard.Program::Main()
Scope Name
FjEAI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FjEAI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
184
Main Method
System.Void SystemDashboard.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SystemDashboard.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SystemDashboard.MainForm.resources
SystemDashboard.Properties.Resources.resources
FRcby
[NBF]root.Data
[NBF]root.Data-preview.png
LayerT
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙