Suspicious
Suspect

75c2c8fa5ed5d3f955f8bc619e31e64b

PE Executable
MD5: 75c2c8fa5ed5d3f955f8bc619e31e64b
Size: 526.34 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 75c2c8fa5ed5d3f955f8bc619e31e64b
Sha1 28758d4b4bf283c1ceffa54789ae0d7408a34691
Sha256 d20f814c949d8aaefbb38fd7fc5a3d51358e209c88bb40ed611ab34802e3fd9b
Sha384 9595d2d17b87704805c3fe77abc99766b61d0d1a23b8f9d752c2ed81628e93e86be3896dfc00ce1c383d6dd5f95e096d
Sha512 52399a6cc5a442587407dbcad74134a9a6d7585fe92f3aa2f8f8c737092fe628e754694f022a334073a39fee8f6d22ffee210a120c3eae40652d74e4acc3c219
SSDeep 12288:oQmgELXkhnrdLfoHdGb84zSf5Bmp+OGKgP67P2Jpnb0Ux/:oQPnroU8ESf5Ip+FKg6P6nb0UB
TLSH 3AB402556B95EA62E8F947F00D30E2725336AFCDE011C30FAEEAACEBB85171424552D3
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RealtekAudio.Properties.Resources.resources
JgqH
sik
Name Value
Module Name
vjPi.exe
Full Name
vjPi.exe
EntryPoint
System.Void RealtekAudio.Program::Main()
Scope Name
vjPi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vjPi
Assembly Version
6.1.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
311
Main Method
System.Void RealtekAudio.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RealtekAudio.VirtualForm81::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
vjPi.exe
Full Name
vjPi.exe
EntryPoint
System.Void RealtekAudio.Program::Main()
Scope Name
vjPi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vjPi
Assembly Version
6.1.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
311
Main Method
System.Void RealtekAudio.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RealtekAudio.VirtualForm81::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RealtekAudio.Properties.Resources.resources
JgqH
sik
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
75c2c8fa5ed5d3f955f8bc619e31e64b
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
75c2c8fa5ed5d3f955f8bc619e31e64b
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙