Suspicious
Suspect

787a6815a3cd7c3fa7d89b572450f79d

PE Executable
MD5: 787a6815a3cd7c3fa7d89b572450f79d
Size: 820.22 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 787a6815a3cd7c3fa7d89b572450f79d
Sha1 26ee7f84e01751e892468a356e0bdf8188e9ceaf
Sha256 db47c4ee320a21f6ddcf2544403b3ae658bedf18c15e25cf2c9a4b39bce0cc07
Sha384 8cf536fab1ec76c03c041a9807ca31c75ec991973b3f8060a64835aeeaa23ba4a3b336619c4538071854184beeafc00b
Sha512 f6c3b7e51a26fd2abcda76684cf21877df7db3b4ca45b240cb76f8e50d97f7cbeef01cd985aa3992828dc99037e5ef9361590ff86310d409005d6c66fe000216
SSDeep 12288:c5X5xAMCGBpMkQ7jqANmnjb5cf2jWdb8jmWZ8Gwp2iVUvNTsFKN:BM7BpFQ3B4OmWdbzKbGUvNPN
TLSH 4605011433AACF06D9B607B81D30F37553BA6C4DA620D2578FE46DEB3935F9128186A3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SemaphoreLine.Properties.Resources.resources
GUI
[NBF]root.Data
bJNl
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
TJxN.exe
Full Name
TJxN.exe
EntryPoint
System.Void SemaphoreLine.Program::Main()
Scope Name
TJxN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TJxN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
417
Main Method
System.Void SemaphoreLine.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SemaphoreLine.Formlar.HatForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SemaphoreLine.Properties.Resources.resources
GUI
[NBF]root.Data
bJNl
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙