Suspicious
Suspect

cec50a835d12c05a0810692970d500f4

PE Executable
MD5: cec50a835d12c05a0810692970d500f4
Size: 998.4 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 cec50a835d12c05a0810692970d500f4
Sha1 b15d383f51fbce803b5bcfdac16e709cba8bd9ac
Sha256 bd231e1e461b363b43a36d85b6afc39ec93ca892feaad685f6e373ea40ba39f5
Sha384 be7dafd5a21f2cf5fa9dd4a184eb367f1c2963869fcfa8dad088486d55bb6e76d3b4cfe50157ec5c6c19abda2931443c
Sha512 f09c2c6be66b58c2a4fa2f42b73cf8de3267af9c903d1b00cbb54ae0e0cc55e41989b266bf5f06c4a19c637e021a896b70ab5274de5b0c9de0da3ae5fef4905b
SSDeep 12288:Th69IGe62fyKgwrXadP4h6/dbKB+VZZ+6TW+/MwhOj7o0qpfAL+0OWKsb:V6WGv2f5gwTIAh6/dbK2ZZrnEp7gfD
TLSH 5E25BFF1B211C869E4F714B9BA49CA7030D7FDAD8990C20D52DDBD6B74B3382109AE5B
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HabitTracker.MainForm.resources
HabitTracker.Properties.Resources.resources
JZEq
[NBF]root.Data
[NBF]root.Data-preview.png
KS
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: GcmJ.pdb
Module Name
GcmJ.exe
Full Name
GcmJ.exe
EntryPoint
System.Void HabitTracker.Program::Main()
Scope Name
GcmJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
GcmJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
110
Main Method
System.Void HabitTracker.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HabitTracker.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HabitTracker.MainForm.resources
HabitTracker.Properties.Resources.resources
JZEq
[NBF]root.Data
[NBF]root.Data-preview.png
KS
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙