Suspicious
Suspect

61f9426a8047db9bd98c7ad5402e615f

PE Executable
MD5: 61f9426a8047db9bd98c7ad5402e615f
Size: 725.5 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 61f9426a8047db9bd98c7ad5402e615f
Sha1 8694b4d04e1a3e60be3d6477606a7e0151a5a42c
Sha256 bccfcd6d033f0b10c02a00ce207d997a6e37534715b415b40937154d51dc47be
Sha384 baf8c931a51abae8d1dbde0e973b4371207b5e689b7c653bcafc24f880060688c18ff464176f03f5b29bff69aea5a3a8
Sha512 4a5e518fcdc9660e519c37002a628a8f3b8b9ea818e43bfb65b578d89cca060cea85634aaafc0dc899ce083f014b38f9784bcc893b5f4d5f4897f4cbb50b9ab0
SSDeep 12288:dEA4ctN7IBWXWWa/35BpQrcD+CzBpbkMGzDMoM8RkSHPbY+2Hzq1Jwk7Kzs:LTrI7BcYKCIMKMoMykSHTY9zqbwk7Kz
TLSH E7F40104225AD903C1D24FB6B971E3B03B389EDBA9A1E2936FC93FDF70366944951346
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BackupSync.Form1.resources
BackupSync.Properties.Resources.resources
Ch1
[NBF]root.Data
dvzr
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: pLJc.pdb
Module Name
pLJc.exe
Full Name
pLJc.exe
EntryPoint
System.Void BackupSync.Program::Main()
Scope Name
pLJc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pLJc
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
125
Main Method
System.Void BackupSync.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BackupSync.Form4::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
pLJc.exe
Full Name
pLJc.exe
EntryPoint
System.Void BackupSync.Program::Main()
Scope Name
pLJc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pLJc
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
125
Main Method
System.Void BackupSync.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BackupSync.Form4::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BackupSync.Form1.resources
BackupSync.Properties.Resources.resources
Ch1
[NBF]root.Data
dvzr
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙