Suspicious
Suspect

39e6999460053cd41eea79e0eb247854

PE Executable
MD5: 39e6999460053cd41eea79e0eb247854
Size: 955.39 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 39e6999460053cd41eea79e0eb247854
Sha1 b6125549727d2713c864810471904bb3154e101b
Sha256 c5b8dcac999dedc765dd0d39bd6ecf08edd6151819c0affb56156706f2d71d22
Sha384 f1d3e56599d5aead5dec6db3de9fd3eb33b2d48e652edab1241b91f1ac311a8bb6d54524e24428411ee7edebffc74f79
Sha512 58c6d788a6ddf9ea3953f0790978db36247d74f5ffbacd3e93aaf27e2f78ac85d9a295e3c67ee1514a51890bbb64d74e544259ece9d667e65567e0f6bc42f98b
SSDeep 12288:4kJ+a6y+hkwfOMksJuHW6ybJOkqH3Kj2h78Tx8tMXMTYR3fyZj1grLZpFhmWJRNw:d+SwWRshtqH6CwqWX/aZ6rNpzNC4g
TLSH D515DF2932EC9A41E57A57BC1174E13027FA7A4D252BE38E4DC228D33EB67410B1B75B
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WindowsFormsApp4.Add_Employee.resources
gYMDataSet.TrayLocation
gYMDataSetBindingSource.TrayLocation
guna2AnimateWindow1.TrayLocation
gymBindingSource.TrayLocation
gymBindingSource1.TrayLocation
gymBindingSource2.TrayLocation
gymTableAdapter.TrayLocation
membershipBindingSource.TrayLocation
membershipTableAdapter.TrayLocation
WindowsFormsApp4.Add_Gym.resources
fillByToolStrip.TrayLocation
gYMDataSet.TrayLocation
gymBindingSource.TrayLocation
gymTableAdapter.TrayLocation
WindowsFormsApp4.Add_Member.resources
gYMDataSet.TrayLocation
gYMDataSetBindingSource.TrayLocation
gymBindingSource.TrayLocation
gymTableAdapter.TrayLocation
membershipBindingSource.TrayLocation
membershipTableAdapter.TrayLocation
WindowsFormsApp4.Add_trainer.resources
gYMDataSet.TrayLocation
gYMDataSetBindingSource.TrayLocation
guna2AnimateWindow1.TrayLocation
membershipBindingSource.TrayLocation
WindowsFormsApp4.Add.resources
WindowsFormsApp4.Properties.Resources.resources
Wadi2012
bGFn
Name Value
Module Name
IWHr.exe
Full Name
IWHr.exe
EntryPoint
System.Void WindowsFormsApp4.Program::Main()
Scope Name
IWHr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
IWHr
Assembly Version
4.7.2025.182
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
2447
Main Method
System.Void WindowsFormsApp4.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WindowsFormsApp4.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WindowsFormsApp4.Add_Employee.resources
gYMDataSet.TrayLocation
gYMDataSetBindingSource.TrayLocation
guna2AnimateWindow1.TrayLocation
gymBindingSource.TrayLocation
gymBindingSource1.TrayLocation
gymBindingSource2.TrayLocation
gymTableAdapter.TrayLocation
membershipBindingSource.TrayLocation
membershipTableAdapter.TrayLocation
WindowsFormsApp4.Add_Gym.resources
fillByToolStrip.TrayLocation
gYMDataSet.TrayLocation
gymBindingSource.TrayLocation
gymTableAdapter.TrayLocation
WindowsFormsApp4.Add_Member.resources
gYMDataSet.TrayLocation
gYMDataSetBindingSource.TrayLocation
gymBindingSource.TrayLocation
gymTableAdapter.TrayLocation
membershipBindingSource.TrayLocation
membershipTableAdapter.TrayLocation
WindowsFormsApp4.Add_trainer.resources
gYMDataSet.TrayLocation
gYMDataSetBindingSource.TrayLocation
guna2AnimateWindow1.TrayLocation
membershipBindingSource.TrayLocation
WindowsFormsApp4.Add.resources
WindowsFormsApp4.Properties.Resources.resources
Wadi2012
bGFn
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
39e6999460053cd41eea79e0eb247854
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
39e6999460053cd41eea79e0eb247854
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙