Suspicious
Suspect

4c5783dcc6dccedf17bc2d5352beb27f

PE Executable
MD5: 4c5783dcc6dccedf17bc2d5352beb27f
Size: 808.96 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 4c5783dcc6dccedf17bc2d5352beb27f
Sha1 73a159be6cce4d2dce12e190d107b72ceacebb8b
Sha256 c948ad083bfa08ede99c76cdafa83866cb46983cbbe0df5aba6f9bebfe4abaf5
Sha384 8df41f1f16f90d931180e4ede4234ecce507f207b108ccf2e181839e552c292bc8ea71f52b6f9bb2edd9321f22895c60
Sha512 a9c94c9ab29d4f1db27befad49d1538a874f48b5940c952380389adc704f5e8974e62cad37f75e7bf222cddb091828cdd7a803a00c507e2329aa395b4422052c
SSDeep 12288:mKqOZQ8rmiKF9B0jKCJUXyyNsaxN/o/dKanpNhWIZLTnk+KuE5bD80BrJj+VJ1:1RQgCKu9hZUlKcThWKLI+KuID80Fib
TLSH FA05E1052F8DC9D9D4F2CAF15973E1B00E3C9EA4AD56D2328ED53F9BF13EA108A41562
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HigurashiDaybreakConfig.FormConfig.resources
$this.Icon
[NBF]root.IconData
IO
[NBF]root.Data
HigurashiDaybreakConfig.FormMyConf.resources
HigurashiDaybreakLauncher.Properties.Resources.resources
REUW
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\tkmCuRFnZV\src\obj\Debug\RNJp.pdb
Module Name
RNJp.exe
Full Name
RNJp.exe
EntryPoint
System.Void HigurashiDaybreakConfig.Program::Main()
Scope Name
RNJp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RNJp
Assembly Version
2.9.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
100
Main Method
System.Void HigurashiDaybreakConfig.Program::Main()
Main IL Instruction Count
49
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HigurashiDaybreakConfig.FormConfig::.ctor()
stloc.0 <null>
newobj System.Void HigurashiDaybreakConfig.DXEnvironment::.ctor()
stloc.1 <null>
ldloc.1 <null>
callvirt System.String HigurashiDaybreakConfig.DXEnvironment::getGameLocation()
stloc.2 <null>
ldloc.2 <null>
ldstr 
call System.Boolean System.String::op_Equality(System.String,System.String)
stloc.3 <null>
ldloc.3 <null>
brfalse.s IL_0062: ldloc.2
nop <null>
ldstr Please set your game folder location.
ldstr Important
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String)
pop <null>
newobj System.Void HigurashiDaybreakConfig.FormMyConf::.ctor()
stloc.s V_4
ldloc.s V_4
ldloca.s V_1
callvirt System.Void HigurashiDaybreakConfig.FormMyConf::setConfig(HigurashiDaybreakConfig.DXEnvironment&)
nop <null>
ldloc.s V_4
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ldloc.1 <null>
callvirt System.String HigurashiDaybreakConfig.DXEnvironment::getGameLocation()
stloc.2 <null>
nop <null>
ldloc.2 <null>
ldstr 
call System.Boolean System.String::op_Inequality(System.String,System.String)
stloc.s V_5
ldloc.s V_5
brfalse.s IL_007C: ret
nop <null>
ldloc.2 <null>
call System.Void HigurashiDaybreakConfig.Program::startApp(System.String)
nop <null>
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HigurashiDaybreakConfig.FormConfig.resources
$this.Icon
[NBF]root.IconData
IO
[NBF]root.Data
HigurashiDaybreakConfig.FormMyConf.resources
HigurashiDaybreakLauncher.Properties.Resources.resources
REUW
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙