Suspicious
Suspect

PE Executable
MD5: 5bf8f9e29edce7fc1b75207a7912f014
Size: 728.58 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 5bf8f9e29edce7fc1b75207a7912f014
Sha1 0e42ca6a7fb501a6785621749d09d523391e5bda
Sha256 95c305c5d89970d7d4fbbe0649543d2286d21c678af50ef80ceebb360b0a3cbf
Sha384 bb6296435bd025768c4935753b229b8b9aa67329b9a3764ee5a97033dcee1c0899d32f620f90dbbbcbf7a95eb7453ddf
Sha512 3f5601f994be2fb9048ade993a73e88fde7b89b05eef25dc55dfcd82e7d7691700e6e5872ec6aaad089f5e7edfbaf9cff9a378edaca68a19e57dd9c86810e27c
SSDeep 12288:m0d1yFvFzyRCKgNUGJc1KYxpxaKIdx3ufU5PXZoh1A0OWR:mayFv9FKOU3nxpxDIdf5PJ4h
TLSH 4FF412993796D903D4A013B05CF0D375A22E2F99B812DB475EE8ADDB383AF412CD4396
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
LoremMaker.Forms.MainForm.resources
LoremMaker.Properties.Resources.resources
GejK
[NBF]root.Data
[NBF]root.Data-preview.png
KS
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: sTJN.pdb
Module Name
sTJN.exe
Full Name
sTJN.exe
EntryPoint
System.Void LoremMaker.Program::Main()
Scope Name
sTJN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sTJN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
350
Main Method
System.Void LoremMaker.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void LoremMaker.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
LoremMaker.Forms.MainForm.resources
LoremMaker.Properties.Resources.resources
GejK
[NBF]root.Data
[NBF]root.Data-preview.png
KS
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙