Suspicious
Suspect

PE Executable
MD5: 68e787831bccd0a9dbd67d5fe57ce761
Size: 535.05 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 68e787831bccd0a9dbd67d5fe57ce761
Sha1 c390f7c599f7d8c70812d3738f30f690e036f489
Sha256 2a326dcd2257005284073b14f534ba7a4a6e2ada8d9ec1d8df1f72789366d055
Sha384 4963679efe5ce055a2ff0eb346854884be321dace9ac76da857e1fce3bc645142f2847f9a41728dc2393d3161f7e337c
Sha512 c4216eaadf27eb76ba3954667ae85ba687583175e55957cde4738bcd728a392c9881ea643d3f44868b22e864dd135b51af111984f4bad81ff46aa4d73267ba9a
SSDeep 12288:hVoJPgRD2K6B6XwWd+5W/GQ409kjyGJPztq0rlIJYkR:aPED2Ki8AAGZKo1rl+P
TLSH E9B4BEE03A75771ACEA10A70E678EDB682F41D687010BAF759DD7B87749C210AE0CF46
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorCodes.Form1.resources
ColorCodes.Properties.Resources.resources
GoOj
[NBF]root.Data
[NBF]root.Data-preview.png
SmallCatttt
[NBF]root.Data
[NBF]root.Data-preview.png
V6
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x7F400 size 13832 bytes
Info
PDB Path: DjIU.pdb
Module Name
DjIU.exe
Full Name
DjIU.exe
EntryPoint
System.Void ColorCodes.Program::Main()
Scope Name
DjIU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DjIU
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
213
Main Method
System.Void ColorCodes.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ColorCodes.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
DjIU.exe
Full Name
DjIU.exe
EntryPoint
System.Void ColorCodes.Program::Main()
Scope Name
DjIU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DjIU
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
213
Main Method
System.Void ColorCodes.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ColorCodes.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorCodes.Form1.resources
ColorCodes.Properties.Resources.resources
GoOj
[NBF]root.Data
[NBF]root.Data-preview.png
SmallCatttt
[NBF]root.Data
[NBF]root.Data-preview.png
V6
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙