Suspicious
Suspect

a0b2deb23eb23221d713916f461230bb

PE Executable
MD5: a0b2deb23eb23221d713916f461230bb
Size: 1.63 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 a0b2deb23eb23221d713916f461230bb
Sha1 a6ca175a3e90cb6ed4821199638c6ddf898abebd
Sha256 3fd9f4172c8588c4df27fff1875a78da23ddc8242c0b3d07f87d45020c0d475d
Sha384 818a47b55cce09ea94837f7b3cb496ed4d3e6ae2a624d045c7b2e134b978f109d98d3111f3c5a42e86c13df434be410a
Sha512 8df99b95087317720c658f6964aaa18c9fe5052da965bcbc6bd70ecb9b7bb1b4ef174d315534d63436fcae9162ab13c4f296d11da5b2b17b8532406d75224c6d
SSDeep 49152:x3KlIH3MJjDj7477rhEj2PAcFMmu2NmJDM:x3KWHQjDmu6qD
TLSH D3751251765CC91ADCA807B1C936C3F51365BE8AE911F21B8ADA7FFB3639E131804782
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CloudJar.Properties.Resources.resources
UDP
[NBF]root.Data
afwt
[NBF]root.Data
[NBF]root.Data-preview.png
CloudJar.RegulierungForm.resources
$this.Icon
[NBF]root.IconData
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
yxzJ.exe
Full Name
yxzJ.exe
EntryPoint
System.Void CloudJar.Program::Main()
Scope Name
yxzJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yxzJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
248
Main Method
System.Void CloudJar.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CloudJar.HauptForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
yxzJ.exe
Full Name
yxzJ.exe
EntryPoint
System.Void CloudJar.Program::Main()
Scope Name
yxzJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yxzJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
248
Main Method
System.Void CloudJar.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CloudJar.HauptForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CloudJar.Properties.Resources.resources
UDP
[NBF]root.Data
afwt
[NBF]root.Data
[NBF]root.Data-preview.png
CloudJar.RegulierungForm.resources
$this.Icon
[NBF]root.IconData
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙