Suspicious
Suspect

cad519704ef32fd0fc508256719b0e8a

PE Executable
MD5: cad519704ef32fd0fc508256719b0e8a
Size: 807.94 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 cad519704ef32fd0fc508256719b0e8a
Sha1 064858bdaab8df1c79920c46f25e9ad26b041947
Sha256 deadfb57cd54af6fc0fd10b8bdc065b67a9b43eb3868bb1c9442572f0efa62b3
Sha384 509c8720b9db6687175f4473842c070b099cd78dbda1b5f3fb005b1935d86e0cc6de0d76aa746b8e9b58de40496744e9
Sha512 4dcff571c3c8ade4160988496e88836ac73ef3d02613fd7b174df3009bc3d9e5b679ab75de8c96e6d76a6dc5c96ce692070c42901b6ae6e207d72a27c11b1c4a
SSDeep 24576:YMAqwnwcjt69U9tbAM5VWY0ZtEIBF0Djlm:gjjt6G9tXn01BmP
TLSH 3E05EF546D5DAB1EECA463F4C870F27107F1ACA86826E60A4EE93CE77B13B0D1215763
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SoftwareMercado.frmPrincipal.resources
$this.Icon
[NBF]root.IconData
gr
[NBF]root.Data
SoftwareMercado.Properties.Resources.resources
hUFe
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
pgjt.exe
Full Name
pgjt.exe
EntryPoint
System.Void SoftwareMercado.Program::Main()
Scope Name
pgjt.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pgjt
Assembly Version
3.7.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
573
Main Method
System.Void SoftwareMercado.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SoftwareMercado.frmPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
?huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SoftwareMercado.frmPrincipal.resources
$this.Icon
[NBF]root.IconData
gr
[NBF]root.Data
SoftwareMercado.Properties.Resources.resources
hUFe
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
?huhuhuhu
cad519704ef32fd0fc508256719b0e8a
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙