Suspicious
Suspect

PE Executable
MD5: ccca6ff8a6755174057243021b6554f4
Size: 784.38 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 ccca6ff8a6755174057243021b6554f4
Sha1 9d59df29a484899cd8608538ed2a00905a67be16
Sha256 a6b23e40180f192dcca45083239c786ccc52ce09836996dd4e6271fcef0e3374
Sha384 82648767a988f3270a94c1b0fc8f4b6fe1de27b8b1c31a783a7cccf6c97551cb5e6da523bc287dbdae4527407325072a
Sha512 06a2e88d4e2b850d7d2e8044bc2fc0cb70c9ec1220041bb7ec1d0f2f944b31ba148134a129a57085acdf1ff4db2cae9a4b6b3aba15b4204bc130c32770728f39
SSDeep 12288:wBBf7ABzrq4Vxizven54QFX/vTMCAeScXtMhp4y2tTNQQpIsX5Q5o+:wvf7AU4DiuuQFX/v4CHSPhIgQisJ
TLSH 99F412487B4AED02C9816FF409A1E37563788F5CF820D62B8FE96CDBB06DE55381C291
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
testeMatematico.Form1.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
CHT
[NBF]root.Data
timer1.TrayLocation
testeMatematico.Properties.Resources.resources
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
wIRE
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
JYJO.exe
Full Name
JYJO.exe
EntryPoint
System.Void testeMatematico.Program::Main()
Scope Name
JYJO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JYJO
Assembly Version
2.2.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
104
Main Method
System.Void testeMatematico.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void testeMatematico.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
testeMatematico.Form1.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
CHT
[NBF]root.Data
timer1.TrayLocation
testeMatematico.Properties.Resources.resources
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
wIRE
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙