Suspicious
Suspect

PE Executable
MD5: aee49c76812ae17342fa187fd1a6f639
Size: 620.03 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 aee49c76812ae17342fa187fd1a6f639
Sha1 59fde0de8196e9c3e42cc8e615424551861a8d0b
Sha256 35cd26db3de4420e0442ef5cf452e7f52519f98f3d3f7d168fb235bda1d8548b
Sha384 3a5789fc1587f2907188519d29ef222043b932878ead5ad1eb3761baf0e60ee1826e1d70b64135ccadda83e42315551f
Sha512 fe11bf32b72712412242f82a3a1b1c1d640d1ad3fc87d05539957f3b57524e5202627aa62450dfc64044f5641a19c4ed854cbd821c8fcc01931741eebcfe8a94
SSDeep 12288:hNbrQ6QcVVZKM5SEVr94IzES0UliZVT7B+7DfHe0pH:PfXZKVErrzESJEp+7qA
TLSH 74D4EF6716EBF831F4B2D6321C20F2F862BD5DB6541386128BDB3FAB3E2617565042D2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Ping_Pong.Form1.resources
$this.Icon
[NBF]root.IconData
nch
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
timer1.TrayLocation
ListingMatcher.Properties.Resources.resources
RlNe
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: Jvgo.pdb
Module Name
Jvgo.exe
Full Name
Jvgo.exe
EntryPoint
System.Void ListingMatcher.Program::Main()
Scope Name
Jvgo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Jvgo
Assembly Version
1.8.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
58
Main Method
System.Void ListingMatcher.Program::Main()
Main IL Instruction Count
22
Main IL
nop <null>
newobj System.Void Ping_Pong.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ldstr products.txt
call System.Collections.Generic.List`1<ListingMatcher.Product> ListingMatcher.JsonIO::JsonDeserialize<ListingMatcher.Product>(System.String)
stloc.0 <null>
ldstr listings.txt
call System.Collections.Generic.List`1<ListingMatcher.Listing> ListingMatcher.JsonIO::JsonDeserialize<ListingMatcher.Listing>(System.String)
stloc.1 <null>
ldloc.0 <null>
ldloc.1 <null>
call System.Collections.Generic.List`1<ListingMatcher.Result> ListingMatcher.Matcher::FindProductToListingMatching(System.Collections.Generic.List`1<ListingMatcher.Product>,System.Collections.Generic.List`1<ListingMatcher.Listing>)
stloc.2 <null>
ldloc.2 <null>
call System.String[] ListingMatcher.JsonIO::JsonSerialize<ListingMatcher.Result>(System.Collections.Generic.List`1<ListingMatcher.Result>)
stloc.3 <null>
ldstr results.txt
ldloc.3 <null>
call System.Void System.IO.File::WriteAllLines(System.String,System.String[])
nop <null>
ret <null>
Module Name
Jvgo.exe
Full Name
Jvgo.exe
EntryPoint
System.Void ListingMatcher.Program::Main()
Scope Name
Jvgo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Jvgo
Assembly Version
1.8.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
58
Main Method
System.Void ListingMatcher.Program::Main()
Main IL Instruction Count
22
Main IL
nop <null>
newobj System.Void Ping_Pong.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ldstr products.txt
call System.Collections.Generic.List`1<ListingMatcher.Product> ListingMatcher.JsonIO::JsonDeserialize<ListingMatcher.Product>(System.String)
stloc.0 <null>
ldstr listings.txt
call System.Collections.Generic.List`1<ListingMatcher.Listing> ListingMatcher.JsonIO::JsonDeserialize<ListingMatcher.Listing>(System.String)
stloc.1 <null>
ldloc.0 <null>
ldloc.1 <null>
call System.Collections.Generic.List`1<ListingMatcher.Result> ListingMatcher.Matcher::FindProductToListingMatching(System.Collections.Generic.List`1<ListingMatcher.Product>,System.Collections.Generic.List`1<ListingMatcher.Listing>)
stloc.2 <null>
ldloc.2 <null>
call System.String[] ListingMatcher.JsonIO::JsonSerialize<ListingMatcher.Result>(System.Collections.Generic.List`1<ListingMatcher.Result>)
stloc.3 <null>
ldstr results.txt
ldloc.3 <null>
call System.Void System.IO.File::WriteAllLines(System.String,System.String[])
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Ping_Pong.Form1.resources
$this.Icon
[NBF]root.IconData
nch
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
timer1.TrayLocation
ListingMatcher.Properties.Resources.resources
RlNe
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙