Suspicious
Suspect

PE Executable
MD5: a6e01cec828067c6add3bf6367b17f3f
Size: 456.7 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 a6e01cec828067c6add3bf6367b17f3f
Sha1 b3a3c34a08c363014f8b5b42ba44d4f25d9954e6
Sha256 26f160d2d097219dd2b6ffa650dfe0d67b854a53fe5bc23e44aff7c0d7559c37
Sha384 5478073c915ee9146b46e65e1ce15e180cd451737b81ba73c29d901845d471c1775fb0b0acc21e6acc8a8eb718ccc309
Sha512 960c71f711a470b57c40295d7011e2e4e9e41d2bc6f3e63c15957564c077743e31972bc11259f8858104b2f3e52bab4ffc71d444e39b9c6c55a78f38468073f8
SSDeep 12288:QKr0OW9EgKx0SPKufcvsYTtpB9U0uO6bwGg:QugKvVShEA
TLSH 01A401983357DE12D9A217F48CB0D3B463A81EDDA402D3079EE9FCCB792B7546980297
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorConvert.MainForm.resources
ColorConvert.Properties.Resources.resources
KS
[NBF]root.Data
YXdL
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: LpSJ.pdb
Module Name
LpSJ.exe
Full Name
LpSJ.exe
EntryPoint
System.Void ColorConvert.Program::Main()
Scope Name
LpSJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LpSJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
140
Main Method
System.Void ColorConvert.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ColorConvert.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorConvert.MainForm.resources
ColorConvert.Properties.Resources.resources
KS
[NBF]root.Data
YXdL
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙