Suspicious
Suspect

PE Executable
MD5: 5bfe9273fd11aa7ac9f5b05542ac4174
Size: 679.94 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 5bfe9273fd11aa7ac9f5b05542ac4174
Sha1 759a7b3cf6c8099d464fa73c4c8e73ecb27a630d
Sha256 adc5532725144b1f28aaf526c1f83fe7ab098a54cdeec6e76de74145a3e793de
Sha384 a31301994b0116b933cc6066db646f5097bb226586fcbfb27dba4829706d866774beda95d1598c00e675e146e672ae12
Sha512 0d25ea020165101bfa035bf0b0b21ce6cf12c66883fcdb7ffaf2ced47d07a00d84253028f5bf7162baa85e7797aa81a7c0a03407275b1f99d1edb9f9322779fd
SSDeep 12288:0if7r0uT4enMoFhw8zo+PsygNzs8MFl/XkHzRTtlptt2IxeH:0if7hTfCAo+UySs88MNTthtl
TLSH 81E4F1156B2EEF12D9A21BF006A1E2B417B49D4DB821E3174FEA7CDB747AF042809743
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpaceCalculator.MainForm.resources
SpaceCalculator.Properties.Resources.resources
CHT
[NBF]root.Data
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
wDim
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: jTot.pdb
Module Name
jTot.exe
Full Name
jTot.exe
EntryPoint
System.Void SpaceCalculator.Program::Main()
Scope Name
jTot.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jTot
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
414
Main Method
System.Void SpaceCalculator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpaceCalculator.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SpaceCalculator.MainForm.resources
SpaceCalculator.Properties.Resources.resources
CHT
[NBF]root.Data
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
wDim
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙