Suspicious
Suspect

PE Executable
MD5: 7acd4df7583164eb019f5dc230707e25
Size: 743.94 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 7acd4df7583164eb019f5dc230707e25
Sha1 f170829b8bff6f6aa175fadf27108765a5afca7c
Sha256 6ef00fa27b22acfceb6239f2af7ca5ae8b8ed95949f596e126f856f881638b9f
Sha384 fbecebb1e2e1c751ee514e11b638f88595da45b5a05b28729e2c5c3ca5282ffff7b15c0a3df9ff5967dd1e904e15c176
Sha512 103c26726e9cbd5c90aa310ea03176b1e5501e43ea6173a0af4df7fd71bbde7aa67088adf35e154aa025174a65cb76c34edb87f03374e5e8f4d25013af5116ba
SSDeep 12288:qVfFdDh1sTXMtB1HPrbmvgFSa2cNJUgdpO2z/w3Zjg+E3xj/wgUFjcG+rkR:IjN/vrb/FSa2+tpOww3Zjg+oG5+u
TLSH 29F401641209D906D5AA8FB41972E3740FB86FC9B422E3039FE9FDEFB436B945940352
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RAMMonitor.Properties.Resources.resources
PAGI
[NBF]root.Data
[NBF]root.Data-preview.png
squid
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xB2400 size 13832 bytes
Info
PDB Path: jqhB.pdb
Module Name
jqhB.exe
Full Name
jqhB.exe
EntryPoint
System.Void RAMMonitor.Program::Main()
Scope Name
jqhB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jqhB
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
194
Main Method
System.Void RAMMonitor.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RAMMonitor.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
jqhB.exe
Full Name
jqhB.exe
EntryPoint
System.Void RAMMonitor.Program::Main()
Scope Name
jqhB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jqhB
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
194
Main Method
System.Void RAMMonitor.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RAMMonitor.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RAMMonitor.Properties.Resources.resources
PAGI
[NBF]root.Data
[NBF]root.Data-preview.png
squid
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙