Suspicious
Suspect

c6409e078bad9094ab4b26dad5219f6c

PE Executable
MD5: c6409e078bad9094ab4b26dad5219f6c
Size: 26.74 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 c6409e078bad9094ab4b26dad5219f6c
Sha1 f372511e07d474f2b4488603cc0a6fd4c780cd7e
Sha256 abfac8026d1974220871568caf9344cbffed19a184ff098c0912ffbb4f1e42d5
Sha384 24917e5e488848941ed0eb345b3fb5ab5f9abeaa4c95d5b21e0c1b8da65b869cd933d2e9543d545eaedee5cc6141a0e9
Sha512 5e981b64b3c0decd0b141fad55444e831eecaef2ef3b211e636e0997d5c42cac8644ce9c5a6903d3c4d1cecfd5d505288cb75942cdfad3d234deb2116d7de114
SSDeep 12288:vgeLTQTFTFTtTQTFTFTgTQTFTFTgTQTFTFTgTQTFTFTtTQTFTFTgTQTFTFTgTQT3:vPjxg
TLSH 4F47C0CD484DA326D892DD2510ED2E2E275C24BBC94A2FB4ECBB3621D70D1D7DA234D6
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
jrnswry_acrhyis.Form1.resources
toolStripButton1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
jrnswry_acrhyis.Properties.Resources.resources
jrnswry_acrhyis_backup
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\jrnswry acrhyis\jrnswry acrhyis\obj\Debug\jrnswry acrhyis.pdb
Module Name
jrnswry acrhyis.exe
Full Name
jrnswry acrhyis.exe
EntryPoint
System.Void jrnswry_acrhyis.Program::Main()
Scope Name
jrnswry acrhyis.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jrnswry acrhyis
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
504
Main Method
System.Void jrnswry_acrhyis.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void jrnswry_acrhyis.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
jrnswry_acrhyis.Form1.resources
toolStripButton1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
jrnswry_acrhyis.Properties.Resources.resources
jrnswry_acrhyis_backup
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙