Suspicious
Suspect

351c67198ac5219bb9787f5807ecebbb

PE Executable
MD5: 351c67198ac5219bb9787f5807ecebbb
Size: 779.26 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 351c67198ac5219bb9787f5807ecebbb
Sha1 8f823e5fff498e15d2a1fb91eee41ab6f043cf12
Sha256 de95c7fdb27d4768c98e3ab9230019ae3ab2f2d54890778c839e6f7be10e2bee
Sha384 6814a675ffb26211c12822c5be8d6f35bff9e1efa65c3034f60dcd89903da92e613b5a0b862f09ab54ce73448bf93d9d
Sha512 d6b74881486da1d16d2cd9e55b35b9363e35752553bee58a1fe0c1e225cca4fcf75e4ec31bf235504037bb214a4cd50ea0eaf99cf4db794ce05f03e95d30a4c0
SSDeep 12288:5a1/nkJsgObeNGuMN/upvVEPR+NREYxlPePF3exV1UnADwjsHkv52:wFkJsgObJuMN/uFSR+xlePF6qzsH
TLSH D0F412186696DF52D9E60BF40530E23603B9AE9FA803C30B4EEBFCEB78113583591597
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModernAdapter.MainForm.resources
ModernAdapter.Properties.Resources.resources
SL
uqxp
Name Value
Module Name
ajTa.exe
Full Name
ajTa.exe
EntryPoint
System.Void ModernAdapter.Program::Main()
Scope Name
ajTa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ajTa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
617
Main Method
System.Void ModernAdapter.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void ModernAdapter.Program::InitializeApplication()
nop <null>
newobj System.Void ModernAdapter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ajTa.exe
Full Name
ajTa.exe
EntryPoint
System.Void ModernAdapter.Program::Main()
Scope Name
ajTa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ajTa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
617
Main Method
System.Void ModernAdapter.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void ModernAdapter.Program::InitializeApplication()
nop <null>
newobj System.Void ModernAdapter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModernAdapter.MainForm.resources
ModernAdapter.Properties.Resources.resources
SL
uqxp
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
351c67198ac5219bb9787f5807ecebbb
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
351c67198ac5219bb9787f5807ecebbb
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙