Suspicious
Suspect

PE Executable
MD5: 3d90bffb9bc2e364d30b190ef76c849f
Size: 776.7 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 3d90bffb9bc2e364d30b190ef76c849f
Sha1 bd92029e67a6a131abe4576624c74b37c5ba13d0
Sha256 3fa202fb6f5dbcfd3faa63fea105e530440204fd747ba386b9a290545453d4d8
Sha384 4726eb5d74ecc8ee7f46b4b4eaa1b12c6fc1c183bd6d878d98f621f4f1e2d3b443eabbcc27f5a69cdc2e9660a67ea830
Sha512 42770f1a722114ac02f40b365e9335a3838fbd9435b734f3efa1d0b8f6af3d1c02ce65e8180afa831241cd9b1608da7ee9526db2fb22968b374b4a55d8104c56
SSDeep 12288:dqa1/nkJsnA5k072FQulkfGgDlGu/WRhD77FW0XmXlGIdpUly9qaBht4QEM:FFkJsz0iGmIlR/yD9WTXlGOpUcBht4R
TLSH FDF4021C7656EB61C9E90FF40520D2B613B7AD9FE410C30B8EE9EDEB7E20354655228B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModernAdapter.MainForm.resources
ModernAdapter.Properties.Resources.resources
SL
btws
Name Value
Module Name
JlHK.exe
Full Name
JlHK.exe
EntryPoint
System.Void ModernAdapter.Program::Main()
Scope Name
JlHK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JlHK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
617
Main Method
System.Void ModernAdapter.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void ModernAdapter.Program::InitializeApplication()
nop <null>
newobj System.Void ModernAdapter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
JlHK.exe
Full Name
JlHK.exe
EntryPoint
System.Void ModernAdapter.Program::Main()
Scope Name
JlHK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JlHK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
617
Main Method
System.Void ModernAdapter.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Void ModernAdapter.Program::InitializeApplication()
nop <null>
newobj System.Void ModernAdapter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ModernAdapter.MainForm.resources
ModernAdapter.Properties.Resources.resources
SL
btws
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
8huhuhuhu
3d90bffb9bc2e364d30b190ef76c849f
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
3d90bffb9bc2e364d30b190ef76c849f
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙