Suspicious
Suspect

PE Executable
MD5: 3518fee3b7c42095fb334064e5107e6b
Size: 770.05 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 3518fee3b7c42095fb334064e5107e6b
Sha1 ab9dba44fa594c51bceb7f6813b7309fab93a5cd
Sha256 649facade465ad92983e7f91f592eed9b04bd84bb4d2d78fcee013dd004f8758
Sha384 31584edfac343274502563658a59473ac575ef3b11d436c3a6cf299fcff2d577af5ce79613fd0599c871636ea5260a4f
Sha512 753a3707be3b676674d9dc572856b6e540bc80d9615787cc74080aa39f02857e13dba4150ee47750d0c9398e120eac6f2f63fe9a0c526a4c2f8fc34bcb9b47a0
SSDeep 12288:cmnbLuRxTs6bmQvB7j7Pds6IOMU4J/iwbWEkf8aafRIixxzajY8RmrVI4q:cmnbLmGQvZjDe3KwqEk2BqmhI
TLSH FDF4120A6DA38491D0693FB4C9F3C1B45A703FDA98B3C7C6BBE63D8F75659016212326
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
Name Value
Module Name
zyjB.exe
Full Name
zyjB.exe
EntryPoint
System.Void FrontEnd.Program::Main()
Scope Name
zyjB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zyjB
Assembly Version
25.174.802.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
228
Main Method
System.Void FrontEnd.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void FrontEnd.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
zyjB.exe
Full Name
zyjB.exe
EntryPoint
System.Void FrontEnd.Program::Main()
Scope Name
zyjB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zyjB
Assembly Version
25.174.802.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
228
Main Method
System.Void FrontEnd.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void FrontEnd.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
3518fee3b7c42095fb334064e5107e6b
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
3518fee3b7c42095fb334064e5107e6b
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙