Suspicious
Suspect

ec7db8b5960a038eb53bd5e159474fd6

PE Executable
MD5: ec7db8b5960a038eb53bd5e159474fd6
Size: 862.72 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 ec7db8b5960a038eb53bd5e159474fd6
Sha1 ecab6a9f6ea86d85f2a02f97a196559582262df7
Sha256 58928c973bd77cabdf6bca123c77f7915c3f335f42e364893c2673d954d22d93
Sha384 a4f9213c4636e9553af5731843c68771a99975a23b9eab84f8dd15d91ebca7b9902f0bb79921951b019dd41e4738728f
Sha512 c76d869d6e8687328f358f2bbbf57732d9132fb95d9d5adabde0196c8031772f2fe22a00102eb796d93dd464743b5bfa3a90e3374b028e8f6cd884672e7e3d20
SSDeep 24576:dUNjR6pFsRmkf0+YTz7ZzBGTgVYHoegkgi+:d+timRmkf0+YTRFwekgi+
TLSH 89050158336ACC02CA935FB15970E3B541B55D99E812E373CEFABE9BB87E3852D01181
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
FleetManager.GlobalDashboardForm.resources
$this.Icon
[NBF]root.IconData
RI
[NBF]root.Data
FleetManager.ContractBiddingForm.resources
FleetManager.Properties.Resources.resources
xSAA
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\HAPTYhEzlZ\src\obj\Debug\JhUw.pdb
Module Name
JhUw.exe
Full Name
JhUw.exe
EntryPoint
System.Void FleetManager.Program::Main()
Scope Name
JhUw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JhUw
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
129
Main Method
System.Void FleetManager.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void FleetManager.GlobalDashboardForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
JhUw.exe
Full Name
JhUw.exe
EntryPoint
System.Void FleetManager.Program::Main()
Scope Name
JhUw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
JhUw
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
129
Main Method
System.Void FleetManager.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void FleetManager.GlobalDashboardForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
FleetManager.GlobalDashboardForm.resources
$this.Icon
[NBF]root.IconData
RI
[NBF]root.Data
FleetManager.ContractBiddingForm.resources
FleetManager.Properties.Resources.resources
xSAA
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙