Suspicious
Suspect

PE Executable
MD5: efde8ff01d21f0fef02c7db8dd5a654b
Size: 707.07 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 efde8ff01d21f0fef02c7db8dd5a654b
Sha1 8a05e1f786ff4e7e4bc4398260b171d6ac8f0933
Sha256 0fb639ad1798449d4dd32d0d4fe0b2076bcd3f22c0ca71123029ddbebc79fbff
Sha384 b6b84acd2dd5631f3cd871a0e5b65a64cb8632bb16769114ce11bacd5817bb62345c59376b07847ca307e00871d2f47f
Sha512 766ba7d23fd09f6f85d79adabeffd6a71a82d09163689d8e658c01fe09c7cfd1c5c1b5630cdf308836d654d6b85ca35a95c73a031633fd132c734c341b1c5005
SSDeep 12288:vD4DFnITt42YmfVRfP8RVsPaHpfllEg+33TDHSVcF7xKa4mIu8Bc6:b4JnITa2YoV8V33E1vHy4Upmxx6
TLSH 16E4024037A8DB12D4E15BF56932C2B45BB43DEEA522C2479EE63EDFB47AB604911303
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AutoWallpaperChanger.Form1.resources
AutoWallpaperChanger.Properties.Resources.resources
FUtkC
[NBF]root.Data
[NBF]root.Data-preview.png
LayerT
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: kXiJU.pdb
Module Name
kXiJU.exe
Full Name
kXiJU.exe
EntryPoint
System.Void AutoWallpaperChanger.Program::Main()
Scope Name
kXiJU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kXiJU
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
211
Main Method
System.Void AutoWallpaperChanger.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AutoWallpaperChanger.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
kXiJU.exe
Full Name
kXiJU.exe
EntryPoint
System.Void AutoWallpaperChanger.Program::Main()
Scope Name
kXiJU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kXiJU
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
211
Main Method
System.Void AutoWallpaperChanger.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AutoWallpaperChanger.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AutoWallpaperChanger.Form1.resources
AutoWallpaperChanger.Properties.Resources.resources
FUtkC
[NBF]root.Data
[NBF]root.Data-preview.png
LayerT
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙