Suspicious
Suspect

PE Executable
MD5: b65d17c12759d25dbfab805a78303dae
Size: 1.22 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 b65d17c12759d25dbfab805a78303dae
Sha1 b3abbb09a40d4d59a2fbbc1b03a5f279cfee7b5e
Sha256 870bf76d2d0b8d4e3ebdcb71d15104343c2b4fdcefdb493e48bf6f9676fcdf05
Sha384 30d25247e7d1292c3435e56e4a40c1838d608ec8fc0b22005d03530ac841869c4954ff6bff83430d90d4da384cf54d26
Sha512 542e6fd16ad6aa36fb14e59ad1b341776c4c5688cdedd51bc614f96fe40f6fad2e4333bb8cbc343c042fc293d478dc93ac8bfe5624b54dcd61992d698a9d60a5
SSDeep 24576:3gfF0Xq/WPIbTYccA2whJJaGrCc/JaDVBQpCWG4MGIvZgmBSH:8Fd/6IbAAVhGGLJaDCGLimB8
TLSH 0D4523DC1627E142C9954B7C05B1F3B5123C6EEDF240D5632EF9ADAFBEA1F042924291
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
HeRoSorter.MainForm.resources
$this.Icon
[NBF]root.IconData
Sort1
[NBF]root.Data
HeRoSorter.Properties.Resources.resources
kJef
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x126E00 size 13832 bytes
Info
PDB Path: ?
Module Name
SjIm.exe
Full Name
SjIm.exe
EntryPoint
System.Void HeRoSorter.Program::Main()
Scope Name
SjIm.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
SjIm
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
63
Main Method
System.Void HeRoSorter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HeRoSorter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
HeRoSorter.MainForm.resources
$this.Icon
[NBF]root.IconData
Sort1
[NBF]root.Data
HeRoSorter.Properties.Resources.resources
kJef
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙