Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 8efa0de4e1a4a20b1201a1debf7171a6
Size: 555.02 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 8efa0de4e1a4a20b1201a1debf7171a6
Sha1 4531bdc8dc2f0129aa59bab076740e0289fc791a
Sha256 3052b8ccdf8f2b0e43ff460d0fa79e75fe741fcbb823fce9ba5d7db8203d0c3a
Sha384 95ce6b31fac117955af3d9fedc8f59ed601feee6abe83d9f022b3c1e33f168ae054ade10b34cb28006425fbaf6c85c38
Sha512 f26c58f5c84df0cd6cf3f42786e94c26a7efa8b24b69b0b132319bb5cfe29a0b23cd153134e0c477ced9f120acb14d55642905ae85ff3ea62b54bc9f3c177fad
SSDeep 12288:Wznnf8rgrSltF/8VCYU63XKAV4pK/NEHMMWbtd5msArkR:knnf8E2ltFMXDKAV4p2gam8
TLSH 3DC401842365DA02C4E64BB15DB2E33447783EC9B811C30B9EEAFDDB7875B4469813A7
PeID
Armadillo v4.x
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNetworkAnalyzer.Forms.MainForm.resources
SmartNetworkAnalyzer.Properties.Resources.resources
greyder
[NBF]root.Data
ogx
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
Cjh.exe
Full Name
Cjh.exe
EntryPoint
System.Void SmartNetworkAnalyzer.Program::Main()
Scope Name
Cjh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Cjh
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void SmartNetworkAnalyzer.Program::Main()
Main IL Instruction Count
26
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
nop <null>
newobj System.Void SmartNetworkAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0040: ret
stloc.0 <null>
nop <null>
ldstr An unexpected error occurred: {0}

The application will now close.
ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
call System.String System.String::Format(System.String,System.Object)
ldstr Fatal Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0040: ret
ret <null>
PDB Path PATH
Cjhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙