Suspicious
Suspect

3f7841733addbcb2c9ce682c97e6ae6c

PE Executable
MD5: 3f7841733addbcb2c9ce682c97e6ae6c
Size: 574.46 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 3f7841733addbcb2c9ce682c97e6ae6c
Sha1 480327c278995074240e7ffc29d50a5cd2a73f6c
Sha256 e97233f6c7b7497a0fe4d6a916dde92ade0cc0f92d73e424af88b0bd855b23db
Sha384 9325d9d33da7f82cd5bd087420baa769bfd9a0be5e87d3b1b6dd6111781da0ee529ba98d1cf9cde9b5b1a9852342bf37
Sha512 a4415cee190604590850dff8bd0783fe4b690d5416e73d3ccadb3e1bb788ad0b3cba3eb5d0562b113f9e960e53a74cc3488f8342688ead3c67aa54c4f1dc00c4
SSDeep 12288:c6VqCV8rVYz+AfjuOfHrATTXR3VMCBK21lRACamBJMjnjf9F:cA3V8rmz3juLxuOK2tXtJMP9
TLSH 6CC412546E9ECB23C1A71B701E75D03097B47D8AE91AD0068FD93FCFB919FA44624283
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoinFlipSimulator.MainFlipForm.resources
CoinFlipSimulator.Properties.Resources.resources
FRuh
[NBF]root.Data
[NBF]root.Data-preview.png
SC
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: JiUO.pdb
Module Name
JiUO.exe
Full Name
JiUO.exe
EntryPoint
System.Void CoinFlipSimulator.Program::Main()
Scope Name
JiUO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JiUO
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
128
Main Method
System.Void CoinFlipSimulator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CoinFlipSimulator.MainFlipForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
JiUO.exe
Full Name
JiUO.exe
EntryPoint
System.Void CoinFlipSimulator.Program::Main()
Scope Name
JiUO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JiUO
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
128
Main Method
System.Void CoinFlipSimulator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CoinFlipSimulator.MainFlipForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoinFlipSimulator.MainFlipForm.resources
CoinFlipSimulator.Properties.Resources.resources
FRuh
[NBF]root.Data
[NBF]root.Data-preview.png
SC
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙