Suspicious
Suspect

PE Executable
MD5: 92d0a3900e0fa5d17c648329302dc041
Size: 906.75 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 92d0a3900e0fa5d17c648329302dc041
Sha1 1ccd42039c46d7a94cd4cea39d9b18e59fa0c6e2
Sha256 9aaec65c036d7b320fb31cbc73bff93e135eb2e8d3780c4a6dff2b4a5421ec9c
Sha384 ec9746ce23591dd657dbf3beecf4244006597a65623ce5eaec33b719091819b523f3b634a4f531096610aa9a0edc227f
Sha512 feba2026ae4dad82216537e5f6c0afe412ba34a9229ccdac72064866036b55bbba4de001aa9d6bbf6df763d226722293864de6f70ecaa9e801cbcfad0a4e4dee
SSDeep 24576:xVR1FJ3RbRwnLsrft8w3h9a84VdQTTr1Y6y2nnfx:xVR1FtwnLsrl8w3h8lVdQTTa6yCfx
TLSH D21512042B99DE17D0E50BF51C71E7780779AE8EA410D31A8EF9BDEB3C3634499913A2
PeID
Armadillo v4.x
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNetworkAnalyzer.Forms.MainForm.resources
SmartNetworkAnalyzer.Properties.Resources.resources
djD
[NBF]root.Data
[NBF]root.Data-preview.png
greyder
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: yGc.pdb
Module Name
yGc.exe
Full Name
yGc.exe
EntryPoint
System.Void SmartNetworkAnalyzer.Program::Main()
Scope Name
yGc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yGc
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void SmartNetworkAnalyzer.Program::Main()
Main IL Instruction Count
26
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
nop <null>
newobj System.Void SmartNetworkAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0040: ret
stloc.0 <null>
nop <null>
ldstr An unexpected error occurred: {0}

The application will now close.
ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
call System.String System.String::Format(System.String,System.Object)
ldstr Fatal Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0040: ret
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNetworkAnalyzer.Forms.MainForm.resources
SmartNetworkAnalyzer.Properties.Resources.resources
djD
[NBF]root.Data
[NBF]root.Data-preview.png
greyder
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙