Suspicious
Suspect

c4d61be80fdab0473f6b19a9e74c2b1c

PE Executable
MD5: c4d61be80fdab0473f6b19a9e74c2b1c
Size: 636.42 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 c4d61be80fdab0473f6b19a9e74c2b1c
Sha1 54395c3181621900cc34b667c0524d5f76d8c136
Sha256 ef191e2d10681d7e07d403c5a0f5c595fb55c54c9a66ddd6cabdb7af0d6f65b2
Sha384 d3a20495ddfbe03bbd852993c42dc9b82823af018498628b48dc4c5b0e47546186cef614731742d4712424b2e803c94e
Sha512 fa71a38d2c830cf00992544dfef0616f6bf8a47ca2d1ff6d2691312ae73e7d63361b5414e65e128eb087a7b072692a7c1deda74b4abd3b042c76a10ee54a1f70
SSDeep 12288:zedYdztpQdjbijfTZrcJnf037sfngT0X5yvljyu6b5ug69j:zedYdztObijfTZI5f03AfgT04v
TLSH B6D4D09C3615F99FC897D5718E90DE74A6206D6AD306C10386EB1CDFB90DE97EE080A3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
uvYy
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Jnax.exe
Full Name
Jnax.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
Jnax.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Jnax
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‪‫‏‫‮‮‮‭‌‎‌‮‭‌‍‭‫‍‌‍‪‮‫‌‬‭‌‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‌‍‫‪‭‮‌​‍‮‪‫‮‎‪‫‬‪‏‬‏​‍‍‪‬‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::‪‏‎‌‭‬‍‪‎‬‌‬​‫‭​‫‌​‏‮‫‭​‮(System.Windows.Forms.Form)
ret <null>
Module Name
Jnax.exe
Full Name
Jnax.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
Jnax.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Jnax
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‪‫‏‫‮‮‮‭‌‎‌‮‭‌‍‭‫‍‌‍‪‮‫‌‬‭‌‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‌‍‫‪‭‮‌​‍‮‪‫‮‎‪‫‬‪‏‬‏​‍‍‪‬‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::‪‏‎‌‭‬‍‪‎‬‌‬​‫‭​‫‌​‏‮‫‭​‮(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
uvYy
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙