Suspicious
Suspect

PE Executable
MD5: 5528497a86bdd071f6fafc1feece57e7
Size: 1.24 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 5528497a86bdd071f6fafc1feece57e7
Sha1 e07fd631255ce8fa49065b2a102857e66ae4a8f3
Sha256 8f1056c686af9c05496ab2840c9751dab3e23a5d004b4793e62302fc0da5a821
Sha384 e5f7cc8fb7a4f8aa76d5132762ae9f320161aa4a5eb21970d7336e950ade88e6101d03274a9084501cc71e34c13ceee6
Sha512 a421331db8c11d5894258f99fc1136b4919bda89606266bb18ecdf0aab35d5fc37f8353fda052342841ab9b2b884a372665e2a79c0d726c38dd992b11b62751e
SSDeep 24576:f+RQfnKszYQm4WRiiuz2ovhP10l4YbZgpFRCx7UwhInVUqqcqjDmy:2RsnuQmZKqShKGYI+AwhIVUqqcV
TLSH D24523992749C912C56D1B386EF0E1B91B7C6CDAFC42E3638EDE5EAB3D95F104E40242
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PentominoSolver.Forms.MainForm.resources
PentominoSolver.Properties.Resources.resources
Java_Logo
[NBF]root.Data
[NBF]root.Data-preview.png
KEEDoZ
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
R
[NBF]root.Data
[NBF]root.Data-preview.png
Spigot_Logo
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: CjjiFe.pdb
Module Name
CjjiFe.exe
Full Name
CjjiFe.exe
EntryPoint
System.Void PentominoSolver.Program::Main()
Scope Name
CjjiFe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CjjiFe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
102
Main Method
System.Void PentominoSolver.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PentominoSolver.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PentominoSolver.Forms.MainForm.resources
PentominoSolver.Properties.Resources.resources
Java_Logo
[NBF]root.Data
[NBF]root.Data-preview.png
KEEDoZ
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
R
[NBF]root.Data
[NBF]root.Data-preview.png
Spigot_Logo
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙