Suspicious
Suspect

PE Executable
MD5: 7fa30f4968b9602164fba34674c62ea7
Size: 842.75 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7fa30f4968b9602164fba34674c62ea7
Sha1 af8fec7cc9843306e9c604b2dae9498784f85ba0
Sha256 4fcbe167dcd88e72b52ed43a3bc0b27d3a68f64efbd1f23e0113cd9f55a55f12
Sha384 ca977843d6cd53c7d58d4bbbec5938896a2c2027003ab5d36f09268b43692c99af88e61ca58e2657965567df25669923
Sha512 e72637bde3dc643e177749592c07721cefcbb8ae004f4686a31400aafb1134e343898c818a5316a830a168ba2f563b59bf9264fb556ce380ded906a909ad1362
SSDeep 12288:f53qwhbgK+58uGqloDdiF69f9Nf8CbMriymhhv+k/uMIVuZL9:fNXW57GtJ265L/bMriymhhv3JIkZp
TLSH C805F10626AECD03E17A5B7048F1D0B407B52E89E522D69B1FD97EEB7A36BD106C5303
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
XHBe.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Bioacoustics_Analyzer.Properties.Resources.resources
clg
[NBF]root.Data
RPvS
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
XHBe.exe
Full Name
XHBe.exe
EntryPoint
System.Void JNY.NNi::XN9()
Scope Name
XHBe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XHBe
Assembly Version
201.502.607.709
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
538
Main Method
System.Void JNY.NNi::XN9()
Main IL Instruction Count
16
Main IL
br IL_001D: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0011: call System.Void lfA.Af0::GjP()
call System.Void lfA.Af0::GjP()
br IL_0028: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: nop
nop <null>
newobj System.Void Agn.Gg5::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001B: nop
Module Name
XHBe.exe
Full Name
XHBe.exe
EntryPoint
System.Void JNY.NNi::XN9()
Scope Name
XHBe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XHBe
Assembly Version
201.502.607.709
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
538
Main Method
System.Void JNY.NNi::XN9()
Main IL Instruction Count
16
Main IL
br IL_001D: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0011: call System.Void lfA.Af0::GjP()
call System.Void lfA.Af0::GjP()
br IL_0028: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: nop
nop <null>
newobj System.Void Agn.Gg5::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001B: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
XHBe.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Bioacoustics_Analyzer.Properties.Resources.resources
clg
[NBF]root.Data
RPvS
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙