Suspicious
Suspect

45595de94c06c3d7914383a1b0416ef0

PE Executable
MD5: 45595de94c06c3d7914383a1b0416ef0
Size: 801.28 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 45595de94c06c3d7914383a1b0416ef0
Sha1 2b4520d7556495844b5f52d3f3a66d6f9657a38e
Sha256 e5736df87221b67a2e2a614374e1d6353043b95e08448ea9260e103ab18a5c8d
Sha384 d98538f7888b7b3807062da0fca9a21e19fd6ccd807d2c947d37b5591d8c3472c977d4252f485c2ba179c3bcff252ff4
Sha512 66a216e3e9f52f46a2690990973771b9c0db06ea4b12352cb1dbcb919890709acedee873f1e0e9a53ca1bdb10d67e00ae2e17e7745b7679a2a0e0435ea326ae8
SSDeep 24576:V0MeD1oz4wnrcrLN3SSCeTk9h7l+CJ3GohjmUCu:Eez4wgPNNT8hp+Y3GKE
TLSH 8B05F161636AEA01E4FA5FF00971C37007B5BD4EA921D21B1EEAACDF3936B901C54763
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CrashMonitor.CrashReportForm.resources
CrashMonitor.Properties.Resources.resources
CTT
[NBF]root.Data
JdAm
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: JQgJ.pdb
Module Name
JQgJ.exe
Full Name
JQgJ.exe
EntryPoint
System.Void CrashMonitor.Program::Main()
Scope Name
JQgJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JQgJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
474
Main Method
System.Void CrashMonitor.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CrashMonitor.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
JQgJ.exe
Full Name
JQgJ.exe
EntryPoint
System.Void CrashMonitor.Program::Main()
Scope Name
JQgJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JQgJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
474
Main Method
System.Void CrashMonitor.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CrashMonitor.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CrashMonitor.CrashReportForm.resources
CrashMonitor.Properties.Resources.resources
CTT
[NBF]root.Data
JdAm
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙