Suspicious
Suspect

PE Executable
MD5: 9046020c727c31a3fd75c6074d1a7733
Size: 988.16 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 9046020c727c31a3fd75c6074d1a7733
Sha1 d09c97e42cfabcad83c0744defbf3e28ec9e8069
Sha256 688c658457069ba67ff844cb28f409cf8988a15cc22be92b4ac4b62404fbf207
Sha384 b25814a7e505df228c3cb6bb5bd0a5b5102c83cd7fa5bc3f98a2ef23534a11bf77416a3a30bfc225ba38105ccba5cb4c
Sha512 417f87b95a23a5fe3033f95bd19fb386b6adc756065b0386fefbe8827b1495abb9778147c299220ce9fe914e8ca01ca44cff0c2de6a0546af6e7d553f7ee1e74
SSDeep 24576:2qu2VLSV1lZ0NhalCra4to3r4Y7uYVp9kh5d2:2eVLQe/SsNtMcY75VpIP
TLSH 28250258276AEE03D4A70FF019B1E3B00BB85E999512D3438EFABDD7B43A7456D402D2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HandwritePad.Properties.Resources.resources
AF
[NBF]root.Data
ZoGK
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: UJWw.pdb
Module Name
UJWw.exe
Full Name
UJWw.exe
EntryPoint
System.Void HandwritePad.Program::Main()
Scope Name
UJWw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
UJWw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
285
Main Method
System.Void HandwritePad.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HandwritePad.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
UJWw.exe
Full Name
UJWw.exe
EntryPoint
System.Void HandwritePad.Program::Main()
Scope Name
UJWw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
UJWw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
285
Main Method
System.Void HandwritePad.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HandwritePad.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HandwritePad.Properties.Resources.resources
AF
[NBF]root.Data
ZoGK
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙