Suspicious
Suspect

PE Executable
MD5: 31c30ad5e5197c7d6b4a2a597752337a
Size: 1.04 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 31c30ad5e5197c7d6b4a2a597752337a
Sha1 9f266df7ef74f0f1df6c76664dcb13056d7763a3
Sha256 633b7028864efa906f8c371beebc9eb66757e514bcb618bb1464c8e4a9c42d79
Sha384 321db919b27da447079c714d9423d22824df9f7e2ee3a5de9ea82c4d61260dde13ea9bb3602ddb60d5fb426c30a6be7e
Sha512 f8637c451ec7db5e311a0e00b0fc3833e5af3a510f8ed25e9a65926d5c86b5b5445b887bcc60d50f4e47f5cf1f4e16fa5bd0aa2a3783785c8574c0104b282cb6
SSDeep 24576:eKTwnNrwQNSTSaHV2Zkto/WcsfEMrNGyec3qAhnLL5DR4RKS:evE5TSaUZaoBsftwc37hnX5DR
TLSH 8225124821A9EA07D8A60BF15CB0C2B467B52E9EEA35C61ACFCDBDEF7474B100215357
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ITHelpdesk.Forms.LoginForm.resources
$this.Icon
[NBF]root.IconData
KI
[NBF]root.Data
ITHelpdesk.Properties.Resources.resources
XmZQ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
nmFj.exe
Full Name
nmFj.exe
EntryPoint
System.Void ITHelpdesk.Program::Main()
Scope Name
nmFj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nmFj
Assembly Version
9.5.7.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
288
Main Method
System.Void ITHelpdesk.Program::Main()
Main IL Instruction Count
30
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ITHelpdesk.Forms.LoginForm::.ctor()
stloc.0 <null>
nop <null>
ldloc.0 <null>
callvirt System.Windows.Forms.DialogResult System.Windows.Forms.Form::ShowDialog()
ldc.i4.1 <null>
ceq <null>
stloc.1 <null>
ldloc.1 <null>
brfalse.s IL_002F: nop
nop <null>
newobj System.Void ITHelpdesk.Forms.MainDashboardForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
nop <null>
leave.s IL_003D: ret
ldloc.0 <null>
brfalse.s IL_003C: endfinally
ldloc.0 <null>
callvirt System.Void System.IDisposable::Dispose()
nop <null>
endfinally <null>
ret <null>
Module Name
nmFj.exe
Full Name
nmFj.exe
EntryPoint
System.Void ITHelpdesk.Program::Main()
Scope Name
nmFj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nmFj
Assembly Version
9.5.7.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
288
Main Method
System.Void ITHelpdesk.Program::Main()
Main IL Instruction Count
30
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ITHelpdesk.Forms.LoginForm::.ctor()
stloc.0 <null>
nop <null>
ldloc.0 <null>
callvirt System.Windows.Forms.DialogResult System.Windows.Forms.Form::ShowDialog()
ldc.i4.1 <null>
ceq <null>
stloc.1 <null>
ldloc.1 <null>
brfalse.s IL_002F: nop
nop <null>
newobj System.Void ITHelpdesk.Forms.MainDashboardForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
nop <null>
leave.s IL_003D: ret
ldloc.0 <null>
brfalse.s IL_003C: endfinally
ldloc.0 <null>
callvirt System.Void System.IDisposable::Dispose()
nop <null>
endfinally <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ITHelpdesk.Forms.LoginForm.resources
$this.Icon
[NBF]root.IconData
KI
[NBF]root.Data
ITHelpdesk.Properties.Resources.resources
XmZQ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙