Suspicious
Suspect

PE Executable
MD5: 75a434dc1ea351360e7a1e1882e55a07
Size: 1.05 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 75a434dc1ea351360e7a1e1882e55a07
Sha1 42f960d7686e83bdf50640f81a0d83c01547d80b
Sha256 acfd0a48223c3e021532b6f7cfb12e81ebf2903bd706b9a5d45fb1a020dd7902
Sha384 c157fb5317d6c49da2c3ec88f434d9a17609fbf6fdaf5b3dc7da621371db36514fe1034f7eb8004dd2084854f568afca
Sha512 d35dba1daea5bb3c256f5eb42795235484c9265800995d7aedacaca8b78c0d734dfa3fe2f58e894979ef48fac52d38ca90aab6b9a304519c1b67e6aec60e3699
SSDeep 24576:97An/qWAskoeb5iBFdlX+AsDc8QE4l2bwrfgSnam49YS:97An/Zmob+AsjB4l75amNS
TLSH 5E2512482006DA16D86E07B89A92D6F807744E99B912F3178FD4FDEB3E77789490D2C3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SingleQueue.SingleQueue.resources
$this.Icon
[NBF]root.IconData
crc
[NBF]root.Data
Vip.CustomForm.Properties.Resources.resources
LQiF
[NBF]root.Data
[NBF]root.Data-preview.png
Vip.CustomForm.Images.SystemButtons.bmp
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\NGKIwamssT\src\obj\Debug\jVbJ.pdb
Module Name
jVbJ.exe
Full Name
jVbJ.exe
EntryPoint
System.Void SingleQueue.Program::Main()
Scope Name
jVbJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jVbJ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
104
Main Method
System.Void SingleQueue.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SingleQueue.SingleQueue::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SingleQueue.SingleQueue.resources
$this.Icon
[NBF]root.IconData
crc
[NBF]root.Data
Vip.CustomForm.Properties.Resources.resources
LQiF
[NBF]root.Data
[NBF]root.Data-preview.png
Vip.CustomForm.Images.SystemButtons.bmp
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙