Suspicious
Suspect

392f68f00690092ae11ce9e23da408e4

PE Executable
MD5: 392f68f00690092ae11ce9e23da408e4
Size: 787.46 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 392f68f00690092ae11ce9e23da408e4
Sha1 941e1aaff9c8d85f75888ee97e907d3e0677cefe
Sha256 d7efc2af3da4e2bc45068793d6b50d8e32d09f21698be3bafbbd78dbe2af004f
Sha384 b539f0afc4f45b8ddd91e6d3d55b3735f7f08edaaaad0e99e2e3040792670b60594343ea540d9a6ca68e639a8f84a37c
Sha512 2c2a0615d95efb3738459b194ecf4385ca0cfa948ac968c59caa23fbb00eaf5c08ecf39b923d9f22f6318ae8f181d004fb6e60b3f9345beabc92ae4ecb015fa4
SSDeep 12288:lWNzdkg3HU9CarPTTrRVdxJcQp4DeTpw66GADiGbYNdc9ZVYiiuS+7Ykt3:w3HUcsTrj/JcRDed8VrwmZVYr1a
TLSH 92F40224A76ECE12C0A65BB45870E2711374AE4DA911D22BDFF5BDDFB879F102918383
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
conversorImagens.Form1.resources
$this.Icon
[NBF]root.IconData
openFileDialog1.TrayLocation
xfi
[NBF]root.Data
Personel_Kayit.FrmAnaForm.resources
Personel_Kayit.FrmGiris.resources
Personel_Kayit.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
YJlESR
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
RjdfJN.exe
Full Name
RjdfJN.exe
EntryPoint
System.Void Personel_Kayit.Program::Main()
Scope Name
RjdfJN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RjdfJN
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
327
Main Method
System.Void Personel_Kayit.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Personel_Kayit.FrmGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
RjdfJN.exe
Full Name
RjdfJN.exe
EntryPoint
System.Void Personel_Kayit.Program::Main()
Scope Name
RjdfJN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RjdfJN
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
327
Main Method
System.Void Personel_Kayit.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Personel_Kayit.FrmGiris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
conversorImagens.Form1.resources
$this.Icon
[NBF]root.IconData
openFileDialog1.TrayLocation
xfi
[NBF]root.Data
Personel_Kayit.FrmAnaForm.resources
Personel_Kayit.FrmGiris.resources
Personel_Kayit.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
YJlESR
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙