Suspicious
Suspect

PE Executable
MD5: a10f7ffc34e1c63f1fdc8bb8e8a72bbc
Size: 678.91 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 a10f7ffc34e1c63f1fdc8bb8e8a72bbc
Sha1 4d30614211f0049776b44e8fa8d43235c7dc5b4b
Sha256 6f7ec2c8d3c0ef2d5d4e5ea824c0af4264cd08aa0580f04499df5e4b69bc8066
Sha384 d038a13c33e08c204743ca0a40127a47e8ed8e26cc46da083c0b4c9afe0c902dfc935551b266a5ebcbd2aa8db471278c
Sha512 6e679097f134a14e33ed26439a581b2f3155484b53ceec74f8fd8390a21f08b95ad234fe8b0529d996c502720e9e747e9ad0c601205b18ed824c4c33810a018d
SSDeep 12288:ZxamRsA9GaAk589HYOMv80FyrxlLCznHBOCqBiZo/muclZgGViBCPrjx6:ZfRsA9GaL589HbMvbFCxgzHBjqr9clbt
TLSH EDE41265271AC813E0A207F98962E3B6A3B89F9DE411D3465FFD7CEB7C3274164A02D1
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PassGenerator.Forms.MainForm.resources
PassGenerator.Properties.Resources.resources
Ce
[NBF]root.Data
gold_bars
[NBF]root.Data
[NBF]root.Data-preview.png
qjuz
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: YHER.pdb
Module Name
YHER.exe
Full Name
YHER.exe
EntryPoint
System.Void PassGenerator.Program::Main()
Scope Name
YHER.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YHER
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
99
Main Method
System.Void PassGenerator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PassGenerator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PassGenerator.Forms.MainForm.resources
PassGenerator.Properties.Resources.resources
Ce
[NBF]root.Data
gold_bars
[NBF]root.Data
[NBF]root.Data-preview.png
qjuz
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙