Suspicious
Suspect

c99a6f0ab9d6577cfb961b911bead78f

PE Executable
MD5: c99a6f0ab9d6577cfb961b911bead78f
Size: 734.72 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 c99a6f0ab9d6577cfb961b911bead78f
Sha1 7e2a19a78582bbd5043adbf08a74951bc78b62e0
Sha256 a6d4a7d43d4868e871e0caac0ac2cbaa742a1c0a2416ce70c43a5e1c418d4a64
Sha384 df9ee875d051127d4684623b876a1ebcc07868185d1265bb78e6281bae298b708750e83aa643d31c5b2aa1639eebd410
Sha512 0fce3c3cd499b98a8fa278219bc7bf2d6e911de865c755e4e29b34d39e008edd5d6e155fa3d17cfc396dc48bf66503e2ef8c43b85ae0b528040f605b791de843
SSDeep 12288:+GbXRFbxQ4sVlmZfR3hI5TzK0EnXOt2cka6A0aKyRROpDbN:+MRFNh2kfRRqwXOt2cka6ph7pD
TLSH 7AF42315A6A49327C1AD47F553E3127013F13C493222C61D998DB8FFACB2B48A6E47E7
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NJpo.g.resources
DesktopApp.AlwaysOnTop.Windows.Form1.resources
$this.Icon
[NBF]root.IconData
LAA
DesktopApp.AlwaysOnTop.Properties.Resources.resources
olKR
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: NJpo.pdb
Module Name
NJpo.exe
Full Name
NJpo.exe
EntryPoint
System.Void DesktopApp.AlwaysOnTop.App::Main()
Scope Name
NJpo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NJpo
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
100
Main Method
System.Void DesktopApp.AlwaysOnTop.App::Main()
Main IL Instruction Count
10
Main IL
nop <null>
newobj System.Void DesktopApp.AlwaysOnTop.App::.ctor()
stloc.0 <null>
ldloc.0 <null>
callvirt System.Void DesktopApp.AlwaysOnTop.App::InitializeComponent()
nop <null>
ldloc.0 <null>
callvirt System.Int32 System.Windows.Application::Run()
pop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NJpo.g.resources
DesktopApp.AlwaysOnTop.Windows.Form1.resources
$this.Icon
[NBF]root.IconData
LAA
DesktopApp.AlwaysOnTop.Properties.Resources.resources
olKR
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙