Suspicious
Suspect

PE Executable
MD5: 61792dfa753b584b0b7f8b0fd22076ab
Size: 500.74 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 61792dfa753b584b0b7f8b0fd22076ab
Sha1 db230d045a7eb7f09cb5df8ce00dd54c2be1e520
Sha256 88170c9fa79e032ba011d0c8b8106e480bcb37985833a84cfe4263c778e421b6
Sha384 2a8673e0943819d76574605ebb0f4c70201869280f492c2a8fa5d4dce1e07c9dd1d1a644f4db10ff955cc201c43e9494
Sha512 e13a17094d0094b0e3fe13cd2ee3c0d68e3f3ed3b6da230b7faab744ab0d43ff7c5681dc860766cd3e9601673939edfce732d2d2098fa3b3674ecd8dc9780653
SSDeep 12288:G5/RoLD653sF5OuC/ZePmTXWz96I9UhVizLDDjbnFA:mRoLOBu2ZePmg4I9U+zLDDjb
TLSH 86B402017A2ADD13C4AB06F81C61C2B483BD4DDDA911E7C75FD6AEEB70E1B521A82743
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
jEXp.exe
Full Name
jEXp.exe
EntryPoint
System.Void SectorRepair.Program::Main()
Scope Name
jEXp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jEXp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
320
Main Method
System.Void SectorRepair.Program::Main()
Main IL Instruction Count
7
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void SectorRepair.Program::InitializeApplication()
newobj System.Void SectorRepair.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
jEXp.exe
Full Name
jEXp.exe
EntryPoint
System.Void SectorRepair.Program::Main()
Scope Name
jEXp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jEXp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
320
Main Method
System.Void SectorRepair.Program::Main()
Main IL Instruction Count
7
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void SectorRepair.Program::InitializeApplication()
newobj System.Void SectorRepair.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Embedded Resources UNKNWOWNsuspect
5huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
5huhuhuhu
61792dfa753b584b0b7f8b0fd22076ab
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
61792dfa753b584b0b7f8b0fd22076ab
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙