Suspicious
Suspect

d48ef26bc1867b39286a0f688e77c909

PE Executable
MD5: d48ef26bc1867b39286a0f688e77c909
Size: 467.46 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 d48ef26bc1867b39286a0f688e77c909
Sha1 f93aeae4f0fa593d9f85596aa505f19aa062cb42
Sha256 b994e8cd9cfc2cd2151b70947c845e529bc13cc2a90b4f0633fbe1eea8d50783
Sha384 d7e4bacde6e78e1f0bf737580372702369ddf1c27305853fe352bcc362ab9d5d1a380dfd04b4df922be07a48bcebfc37
Sha512 783938511246295900a62e9fe5ce7c190578493888e5bfa7e95ffe11275f4bd36164ed27441978a1bfa35b2b656fcf0e0ecb81656a3dc095bf40d8bd1c3494c1
SSDeep 12288:ETiHyMaaXM27XxgKcEYbpe6WrsdajeibyMA4kpcszz:E+HyMpXhTcEU9+sY7byMJkmK
TLSH 8AA401A43A99D903C6D617F08EB1E3BC13B44D88A408E7C79EFAFDDB78717501681692
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DirectoryPlus.MainForm.resources
DirectoryPlus.Properties.Resources.resources
RESR
[NBF]root.Data
[NBF]root.Data-preview.png
gilek
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: JtTP.pdb
Module Name
JtTP.exe
Full Name
JtTP.exe
EntryPoint
System.Void DirectoryPlus.Program::Main()
Scope Name
JtTP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JtTP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
161
Main Method
System.Void DirectoryPlus.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void DirectoryPlus.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
JtTP.exe
Full Name
JtTP.exe
EntryPoint
System.Void DirectoryPlus.Program::Main()
Scope Name
JtTP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JtTP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
161
Main Method
System.Void DirectoryPlus.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void DirectoryPlus.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DirectoryPlus.MainForm.resources
DirectoryPlus.Properties.Resources.resources
RESR
[NBF]root.Data
[NBF]root.Data-preview.png
gilek
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙