Suspicious
Suspect

e634daa853d4d5a55ad3ee5d20d336a9

Share on LinkedIn
Print
PE Executable
MD5: e634daa853d4d5a55ad3ee5d20d336a9
Size: 1.09 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 e634daa853d4d5a55ad3ee5d20d336a9
Sha1 8478c8424b0ba031bd8b911e2ecddd344ce65a1c
Sha256 31d293ffa5e55ff2df504ab951b785e902b335974826a9bfbcd4dfb29ab59068
Sha384 29fbfe8d9b0227a47aecd0c9032d349327ff17cd4e7a6fd11e836aa000f6291108d4bf80f6ea4de4f5ca2574e5a5fbc6
Sha512 50e32fff1b0c71705bf6f73c618f3ce2ad2da45cb16b415e63bd69737727bfad952c8a972dd2ac75103873d9f46a72d2308d2ec6989ec6e0eedb78851ff9d4fe
SSDeep 24576:tsZkYeJaaAsAw3lSwKgxKfld7jS9UMQ5YWE:WZgwMEg8DXGPSE
TLSH CF35020423E9CE02D0BB1BB06AB0E27117B42D94E962E34B4EF6BCE77D75B165815393
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HoneyHunter.Properties.Resources.resources
Dynamics1
[NBF]root.Data
iube
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
kWcJ.exe
Full Name
kWcJ.exe
EntryPoint
System.Void HoneyHunter.Program::Main()
Scope Name
kWcJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kWcJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
423
Main Method
System.Void HoneyHunter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HoneyHunter.DorpForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
kWcJ.exe
Full Name
kWcJ.exe
EntryPoint
System.Void HoneyHunter.Program::Main()
Scope Name
kWcJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kWcJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
423
Main Method
System.Void HoneyHunter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HoneyHunter.DorpForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙