Suspicious
Suspect

PE Executable
MD5: bdd08caad711c183654f6c95680f4f73
Size: 1.32 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 bdd08caad711c183654f6c95680f4f73
Sha1 789366587d5365571b76c99130d5528edb2b922e
Sha256 27ec2b5eec31bcba30eb7c61b6d0cd60bb36716a397bdcb40f2061866519cb02
Sha384 94da0c0fcada14893a11bfb1da51caf0606b48e1a5fd72cb6b372d8ab82bdbbfc97fcf052e7d0b7e25c03cbaed60a8d2
Sha512 e34dda5e088cb5883a0e70f33468bf41e36ea58438c7174a9f03d036c5c2af792fb67f65da576064980cfc140110bb45da96df787eec78cdc57706da966901ed
SSDeep 24576:69K1+/o7i6Bko2ZitLX6woz5NqWeiXNPVq8iA8uw3nEV+pS:69YDvBIEB6woz5Rjqb6Oq+pS
TLSH BC5501081759CE03D6A01BF11931E2B05778BEEEBA21D38B8FDEBEDB74A57409954702
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NetworkTools.Form1.resources
NetworkTools.Properties.Resources.resources
Kyrp
[NBF]root.Data
[NBF]root.Data-preview.png
LAN
[NBF]root.Data
WAN
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x13DE00 size 13832 bytes
Info
PDB Path: yjWv.pdb
Module Name
yjWv.exe
Full Name
yjWv.exe
EntryPoint
System.Void NetworkTools.Program::Main()
Scope Name
yjWv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yjWv
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
405
Main Method
System.Void NetworkTools.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NetworkTools.FormMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
yjWv.exe
Full Name
yjWv.exe
EntryPoint
System.Void NetworkTools.Program::Main()
Scope Name
yjWv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yjWv
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
405
Main Method
System.Void NetworkTools.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NetworkTools.FormMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NetworkTools.Form1.resources
NetworkTools.Properties.Resources.resources
Kyrp
[NBF]root.Data
[NBF]root.Data-preview.png
LAN
[NBF]root.Data
WAN
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙