Suspicious
Suspect

69535b9884681d64fcfb422f62ce4b16

PE Executable
MD5: 69535b9884681d64fcfb422f62ce4b16
Size: 633.86 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 69535b9884681d64fcfb422f62ce4b16
Sha1 26b1b88716a627b89e825367602606a00a4960dc
Sha256 d8becc9e6e2f778b79f2fbc7de9d7a922aeab696ba2a799fbcf9ed1267a171d1
Sha384 5f998e86e4422b8c30b2d3403967efa71452a96e94ae2dd22e598eb31522f54bd66ddbdbdd5dad73c663cfda594b9e3a
Sha512 60bcadaacfa7c907bd67d72d6710af2bcd5aeefef940ad4215dd2c81b0688c3d7c12a65d22fdc683cb221c294366bc52e0e20d3bc22c1b1fe773fa9de77d5a57
SSDeep 6144:+t3DD8e/OBjPNEDDEe1OIunBsd6Wpy1SAovVTLCfsYz5EO8VJIHIu7W5hhf2k4hy:EDI4DEe1OIunBXWOoVCsloHXohhff8F
TLSH BCD40119365DDC03C8625AF04512E67823B49E9CA161D3CB8FCB3DDBF6ABB441E12683
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Calculator.Form1.resources
$this.Icon
[NBF]root.IconData
Clear
[NBF]root.Data
menuStrip1.TrayLocation
Calculator.Form2.resources
Calculator.Properties.Resources.resources
CwTC
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Anjw.exe
Full Name
Anjw.exe
EntryPoint
System.Void Calculator.Program::Main()
Scope Name
Anjw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Anjw
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
438
Main Method
System.Void Calculator.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Calculator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Anjw.exe
Full Name
Anjw.exe
EntryPoint
System.Void Calculator.Program::Main()
Scope Name
Anjw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Anjw
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
438
Main Method
System.Void Calculator.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Calculator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Calculator.Form1.resources
$this.Icon
[NBF]root.IconData
Clear
[NBF]root.Data
menuStrip1.TrayLocation
Calculator.Form2.resources
Calculator.Properties.Resources.resources
CwTC
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙