Suspicious
Suspect

50ea33ef1194b891098a8445a0fa9a97

PE Executable
MD5: 50ea33ef1194b891098a8445a0fa9a97
Size: 719.87 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 50ea33ef1194b891098a8445a0fa9a97
Sha1 cde8981adb6bbd110bc1d0f20853f5bc0dbd948b
Sha256 e5a760f448682d093b83e5bddf43e59b3310aa2d0a839dcc2b5436ee8b2a6206
Sha384 ed5a432e7d6cd7b530c5661076e544d279c43e66cbb9513a668341bd46b880e682d461f6469bb880b1b283be773dd7d0
Sha512 fc6dcd817d6238b8bea4ea64997e5610f08acedfae576f900a2d851e10e47e5c41149e4ca77f51b9433d150e5899e6c9f77f9db1bccf2d701aac86cf4f6580a9
SSDeep 12288:fh7bITnkW+hwXouD01OF+hrYK8rrRiIgqZCph/TtWGnqx0oUQWrGJtbWM:ZOV02oG0RYBrAxqsh/wEzoIS
TLSH 8EE4F1083399CA06E0A55BF41932D3B00BB9BEDEE921C2578FE67CDB7A75B845845313
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TrayOrganizer.Form1.resources
TrayOrganizer.Properties.Resources.resources
IU
[NBF]root.Data
knoi
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: jUyg.pdb
Module Name
jUyg.exe
Full Name
jUyg.exe
EntryPoint
System.Void TrayOrganizer.Program::Main()
Scope Name
jUyg.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jUyg
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
389
Main Method
System.Void TrayOrganizer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TrayOrganizer.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
jUyg.exe
Full Name
jUyg.exe
EntryPoint
System.Void TrayOrganizer.Program::Main()
Scope Name
jUyg.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jUyg
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
389
Main Method
System.Void TrayOrganizer.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TrayOrganizer.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TrayOrganizer.Form1.resources
TrayOrganizer.Properties.Resources.resources
IU
[NBF]root.Data
knoi
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙