Suspicious
Suspect

PE Executable
MD5: de506475b8288f6adfe7a570bb0f707f
Size: 7.13 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 de506475b8288f6adfe7a570bb0f707f
Sha1 d2e908e1a271151e761b9039aaa51c428599ad3f
Sha256 57ae7edf153dae62714e31efabe20bcd93fa7f69f9ffe3f69b6150ce0cc7e92c
Sha384 1d745412f345add9bc09db22015f99d2f95f80c81e2bda7954a508779b11c1f5de55e27c5afb18909887898190cd2ca1
Sha512 a1cc277754f2db5c5e408d6b8f642af69d94a5a893e1016d27505deae4faa368be2bd94042d3efd8838dae7cd986c05a6141ad1997a28225650cc73d900f9edf
SSDeep 98304:logpXxSFK7B2T3c1yIKWNUtL7wlnpaTcgsOPVv3VwslTj9BNvbFXuZGFSPZXmH5W:KNG1yLtfKGsOPvwojtxeZGWZa5W
TLSH 1F7633892251602DC541E63149A4ED78E6BC2C772317CA5BA5F32EEB7E4E2979F100F3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WorldClock.Form1.resources
WorldClock.Properties.Resources.resources
Stxv
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
fjAU.exe
Full Name
fjAU.exe
EntryPoint
System.Void WorldClock.Program::Main()
Scope Name
fjAU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
fjAU
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
165
Main Method
System.Void WorldClock.Program::Main()
Main IL Instruction Count
43
Main IL
nop <null>
ldc.i4 411752651
ldc.i4 209906528
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.6 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0082: nop
nop <null>
ldloc.0 <null>
ldc.i4 648769972
mul <null>
ldc.i4 -284120136
xor <null>
br.s IL_0006: ldc.i4 209906528
ldc.i4.0 <null>
call System.Void WorldClock.Program::‏‬‭‪‌‮​‍​‮‭​‫‍‍‌‍‎​‭‏‮‏‏‭‮(System.Boolean)
ldloc.0 <null>
ldc.i4 -1615491569
mul <null>
ldc.i4 416503129
xor <null>
br.s IL_0006: ldc.i4 209906528
newobj System.Void WorldClock.Form1::.ctor()
call System.Void WorldClock.Program::‏‭‌‫‫‌‎‮‌‍‬‌‫‍‎‭‪‫‎‍‎‫‫‫‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 817665788
mul <null>
ldc.i4 -492968580
xor <null>
br.s IL_0006: ldc.i4 209906528
call System.Void WorldClock.Program::‮‏‏‌‪‭‪‭‍‫‍‮‬‭​​‮‌‏‭‭‬‌‬‮()
nop <null>
ldloc.0 <null>
ldc.i4 1027146892
mul <null>
ldc.i4 587357131
xor <null>
br.s IL_0006: ldc.i4 209906528
nop <null>
ret <null>
Module Name
fjAU.exe
Full Name
fjAU.exe
EntryPoint
System.Void WorldClock.Program::Main()
Scope Name
fjAU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
fjAU
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
165
Main Method
System.Void WorldClock.Program::Main()
Main IL Instruction Count
43
Main IL
nop <null>
ldc.i4 411752651
ldc.i4 209906528
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.6 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0082: nop
nop <null>
ldloc.0 <null>
ldc.i4 648769972
mul <null>
ldc.i4 -284120136
xor <null>
br.s IL_0006: ldc.i4 209906528
ldc.i4.0 <null>
call System.Void WorldClock.Program::‏‬‭‪‌‮​‍​‮‭​‫‍‍‌‍‎​‭‏‮‏‏‭‮(System.Boolean)
ldloc.0 <null>
ldc.i4 -1615491569
mul <null>
ldc.i4 416503129
xor <null>
br.s IL_0006: ldc.i4 209906528
newobj System.Void WorldClock.Form1::.ctor()
call System.Void WorldClock.Program::‏‭‌‫‫‌‎‮‌‍‬‌‫‍‎‭‪‫‎‍‎‫‫‫‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 817665788
mul <null>
ldc.i4 -492968580
xor <null>
br.s IL_0006: ldc.i4 209906528
call System.Void WorldClock.Program::‮‏‏‌‪‭‪‭‍‫‍‮‬‭​​‮‌‏‭‭‬‌‬‮()
nop <null>
ldloc.0 <null>
ldc.i4 1027146892
mul <null>
ldc.i4 587357131
xor <null>
br.s IL_0006: ldc.i4 209906528
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WorldClock.Form1.resources
WorldClock.Properties.Resources.resources
Stxv
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙