Suspicious
Suspect

408fde232dc513fa00fc6f0033cfe6bb

Share on LinkedIn
Print
PE Executable
MD5: 408fde232dc513fa00fc6f0033cfe6bb
Size: 985.61 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 408fde232dc513fa00fc6f0033cfe6bb
Sha1 16ddf518f76de5e42e7c21c0ea208c3a7fb26cc0
Sha256 f75c114f83d3d078bd85e7e59cd8a4ed6e8be4a33db6600bd9eda842845ac2fe
Sha384 ebfa00bd7e5349946b7a6d346b8d9183e94bb519d652822a8dbdbc39ecc42691b0e5310e0089c53cbd6a65a35254813c
Sha512 f54aea19d6ee89786dadb62ad2d58a080ab351e0c5e28e58de72492f425f958cb2a207ee812498f02e5a58fd4534ca16aa9ffe0ab7eda378c1e021af4a7a3eec
SSDeep 24576:rNQ4Dh4Tci++bXmtW5khObCXEEo9A46zAIQfJJZyOh1/0b5z1I5H0:r9DYsOXmaojXE79Ar8PJXyOv/SO5H0
TLSH E225227F7208C94BD1F116F001A6D33A13B51C6BE6A1C246E9D2CCDB729B3A15C1939B
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
 .resources
 .resources
$this.Icon
[NBF]root.IconData
PIP
[NBF]root.Data
timer1.TrayLocation
Cycle_Jump_Game.Properties.Resources.resources
AkJt
[NBF]root.Data
[NBF]root.Data-preview.png
t1
[NBF]root.Data
[NBF]root.Data-preview.png
t2
[NBF]root.Data
[NBF]root.Data-preview.png
​         
Name Value
Module Name
iyrY.exe
Full Name
iyrY.exe
EntryPoint
System.Void  ::()
Scope Name
iyrY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iyrY
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
0
Main Method
System.Void  ::()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void  ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
iyrY.exe
Full Name
iyrY.exe
EntryPoint
System.Void  ::()
Scope Name
iyrY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
iyrY
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
0
Main Method
System.Void  ::()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void  ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙