Suspicious
Suspect

PE Executable
MD5: 37e430117a5135e26a95c406894a160c
Size: 1.79 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 37e430117a5135e26a95c406894a160c
Sha1 81f3dfb3734bca05f694bbcd05f207c2bc6df74e
Sha256 53898e8a1aa8fa8b3a0da356ad85cc1215f4d6b5aef341fae96a41085db349a2
Sha384 8a81bdee620b32391d82d327033c45916748760fa9354f4e3526114f2d568e774ca68697cc10915934d5b2e4bb9dc7cc
Sha512 e645e5ada9a4a0ea6d6f806903f83cf137512e1da681010843731d6bf467933660b10a8373708315c80898be7cf018f364b056b141f9ddbe2fd2db66789f813b
SSDeep 49152:qdq4R1lvX/sR/PfeZ114OJTi1U2vsIrubJQsSrOnELzcFdBnitEckmSXvI/:qdq4R1lvX/sR/PmA1z6GbXMFdB14SXv4
TLSH FA8523496109D512E0CA1F340EB0D6B627B44EAEEA22AD03AFCD7FFB757C72418145A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordleClone.AnaForm.resources
WordleClone.Properties.Resources.resources
KI
[NBF]root.Data
xKXj
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
BJVg.exe
Full Name
BJVg.exe
EntryPoint
System.Void WordleClone.Program::Main()
Scope Name
BJVg.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BJVg
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
99
Main Method
System.Void WordleClone.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordleClone.BaslangicForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
BJVg.exe
Full Name
BJVg.exe
EntryPoint
System.Void WordleClone.Program::Main()
Scope Name
BJVg.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BJVg
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
99
Main Method
System.Void WordleClone.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordleClone.BaslangicForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordleClone.AnaForm.resources
WordleClone.Properties.Resources.resources
KI
[NBF]root.Data
xKXj
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙