Suspicious
Suspect

3ca7faec5e51b1fdf5b8daef5c81404d

PE Executable
MD5: 3ca7faec5e51b1fdf5b8daef5c81404d
Size: 816.64 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 3ca7faec5e51b1fdf5b8daef5c81404d
Sha1 4a58ae74a576b603571458b91978724dd35ce357
Sha256 78ebd82a7705f72ad48780803cc540ccd240fe04fd2cd4f092445d624e5197df
Sha384 6e0dc5dc2a0c359a2e960e3de863a85664e9ef5e22cc2ec935dc5ccaed7e87bc553009a56584ef75f7de9d6a7f3a4f52
Sha512 e61b7b5faa8ac46cb7e1678d19febb81a05171d9215b7feb67a19d7de5fcd2f33cd5d8e5ede3799e5a7583af5fc655770f4abdb20413c5f6a1a6e099c27608ae
SSDeep 12288:tgi/r4Z03VmELaJPjNdWk4+Cc9XPi5TIUqxsH2uVHMdqwc:ud03VMx209MwuHPNMA
TLSH 0D0502A56B59DA52D8EA07F40AB5F3B103B45D4EF621D3468FFABCEB3421B521D08243
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CormorantColony.Properties.Resources.resources
VohC
[NBF]root.Data
[NBF]root.Data-preview.png
critsh
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
JODz.exe
Full Name
JODz.exe
EntryPoint
System.Void CormorantColony.Programme::Main()
Scope Name
JODz.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JODz
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
227
Main Method
System.Void CormorantColony.Programme::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CormorantColony.Vues.FormPrincipale::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CormorantColony.Properties.Resources.resources
VohC
[NBF]root.Data
[NBF]root.Data-preview.png
critsh
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙