Suspicious
Suspect

PE Executable
MD5: 4893f7f55d9e5c677d9644c3899b14e5
Size: 680.45 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 4893f7f55d9e5c677d9644c3899b14e5
Sha1 e0103b3135a729b3c991bcb534cdf07247e0cc99
Sha256 44a2b2a04288b8a218d80ea21b9b96de167b844fa7481adfbd48cfdf179aa0df
Sha384 e3ff2a9ab643a1a18df048a5a455fe3397eb799f0f00edbecea41cf7d0bb9bbcbbcc1e8fc4f1e21a90cafd0934b9dba1
Sha512 22711184a8c28298758c45121c7aca2c958be6cadcf7369b989a66ed455c93c774132abbf4c07789987280dda03d0c866645eeb6ed86aa5247e8fadf6cb2feac
SSDeep 12288:3ho2spkCuFU9PI1bDwhOjhF9AaL25ws3jLCxmOlWisg3tzaFeTreI3HU9C:3m2Uh21bDZnSisT+BlWib9Rrp3HUc
TLSH 8CE4F1483B19DE12C4B557F118A0D7B113B9AD0AB521E2275FF6BDEBB07AF112909323
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BitTools.Forms.MainLauncher.resources
BitTools.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
xcSzTb
[NBF]root.Data
[NBF]root.Data-preview.png
xfi
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: gJckZh.pdb
Module Name
gJckZh.exe
Full Name
gJckZh.exe
EntryPoint
System.Void BitTools.Program::Main()
Scope Name
gJckZh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gJckZh
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
456
Main Method
System.Void BitTools.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BitTools.Forms.MainLauncher::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
gJckZh.exe
Full Name
gJckZh.exe
EntryPoint
System.Void BitTools.Program::Main()
Scope Name
gJckZh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gJckZh
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
456
Main Method
System.Void BitTools.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BitTools.Forms.MainLauncher::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BitTools.Forms.MainLauncher.resources
BitTools.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
xcSzTb
[NBF]root.Data
[NBF]root.Data-preview.png
xfi
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙