Suspicious
Suspect

e634daa853d4d5a55ad3ee5d20d336a9

PE Executable
MD5: e634daa853d4d5a55ad3ee5d20d336a9
Size: 1.09 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 e634daa853d4d5a55ad3ee5d20d336a9
Sha1 8478c8424b0ba031bd8b911e2ecddd344ce65a1c
Sha256 31d293ffa5e55ff2df504ab951b785e902b335974826a9bfbcd4dfb29ab59068
Sha384 29fbfe8d9b0227a47aecd0c9032d349327ff17cd4e7a6fd11e836aa000f6291108d4bf80f6ea4de4f5ca2574e5a5fbc6
Sha512 50e32fff1b0c71705bf6f73c618f3ce2ad2da45cb16b415e63bd69737727bfad952c8a972dd2ac75103873d9f46a72d2308d2ec6989ec6e0eedb78851ff9d4fe
SSDeep 24576:tsZkYeJaaAsAw3lSwKgxKfld7jS9UMQ5YWE:WZgwMEg8DXGPSE
TLSH CF35020423E9CE02D0BB1BB06AB0E27117B42D94E962E34B4EF6BCE77D75B165815393
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HoneyHunter.Properties.Resources.resources
Dynamics1
[NBF]root.Data
iube
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
kWcJ.exe
Full Name
kWcJ.exe
EntryPoint
System.Void HoneyHunter.Program::Main()
Scope Name
kWcJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kWcJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
423
Main Method
System.Void HoneyHunter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HoneyHunter.DorpForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
kWcJ.exe
Full Name
kWcJ.exe
EntryPoint
System.Void HoneyHunter.Program::Main()
Scope Name
kWcJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kWcJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
423
Main Method
System.Void HoneyHunter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HoneyHunter.DorpForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HoneyHunter.Properties.Resources.resources
Dynamics1
[NBF]root.Data
iube
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙