Suspicious
Suspect

PE Executable
MD5: adf5809fe308bfe819f6e5b247df05eb
Size: 693.76 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 adf5809fe308bfe819f6e5b247df05eb
Sha1 dd123b5abb98f5f159d030376443dce63d5be438
Sha256 9e8b389a6d2dd273e9252874bc44c2ceaffdfc6102cb204a46330c823404bb08
Sha384 d9ba3b38e4e5bf89360a0dae9094c853a2c2d1d05671386605fa48d96973369681defc33e5e1eecb39dd7834d2a549cc
Sha512 c373a3b23a48300300622f5b258fcc7dc68f0f3b7910e93d11295a326a8fd4dbf07925ba3078f9b9a77ef2e701247c13dfcfb077b193eb0af8a76e3e2a9e3411
SSDeep 12288:O8o7mIrXK6vPmSGziyRmBDn6VhYFyfCQBL+tJLzxeBgd8jTing98Bc6:ODy0XZwJ+D6DN68+tJLlQx6
TLSH 98E41205771ADA07C0E21FB65CB1E2B027B95ECDBCA1E20B8FD97DDFB0396109465252
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SystemDashboard.MainForm.resources
SystemDashboard.Properties.Resources.resources
LCiAm
[NBF]root.Data
[NBF]root.Data-preview.png
LayerT
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: JNzOP.pdb
Module Name
JNzOP.exe
Full Name
JNzOP.exe
EntryPoint
System.Void SystemDashboard.Program::Main()
Scope Name
JNzOP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JNzOP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
184
Main Method
System.Void SystemDashboard.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SystemDashboard.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
JNzOP.exe
Full Name
JNzOP.exe
EntryPoint
System.Void SystemDashboard.Program::Main()
Scope Name
JNzOP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JNzOP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
184
Main Method
System.Void SystemDashboard.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SystemDashboard.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SystemDashboard.MainForm.resources
SystemDashboard.Properties.Resources.resources
LCiAm
[NBF]root.Data
[NBF]root.Data-preview.png
LayerT
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙