Suspicious
Suspect

PE Executable
MD5: f1a584562bde9a0b6814c9bfd5b092b5
Size: 1.15 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 f1a584562bde9a0b6814c9bfd5b092b5
Sha1 1594806a529f15b39b687e75f4382a6220a52105
Sha256 3b31dfbafa384d76f6de58cee45dcbddb88fbe54f21cc095c75963ef737b449a
Sha384 b32dd5ddb34f01619cf56bf40d10b22d4e0a36cfed3f80378069b9aab00eb4788c300a7606b0bfc48e3bfc3c5cfebca5
Sha512 a13c53bdd9443b447f2af81c9a69868b00d61febac9ead7bf728eb142d953d571eed432db7fc8f6163d0ac042d12ec75f36748b838ba5509503a7300f8913667
SSDeep 24576:qguQ5Y9WeirIjHsQW/qiQRZWqv0JFBI4huyDQqsM6e3C7kNOZgxc:juwnryWyiQ7hvIBXuy0qsM6e3C79Sc
TLSH 73352352339DCE4BD0520BF92271D33053B58D2AE842D267CFEDACDFB916AA12569307
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GratitudeJournal.Form1.resources
GratitudeJournal.Properties.Resources.resources
Clear
[NBF]root.Data
_02
[NBF]root.Data
[NBF]root.Data-preview.png
gUgZtF
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
RegisteredChan
Full Name
RegisteredChan
EntryPoint
System.Void UTF8Deco.SoapIdr::Main()
Scope Name
RegisteredChan
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RyOZjU
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
260
Main Method
System.Void UTF8Deco.SoapIdr::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void c.TimerQu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
RegisteredChan
Full Name
RegisteredChan
EntryPoint
System.Void UTF8Deco.SoapIdr::Main()
Scope Name
RegisteredChan
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RyOZjU
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
260
Main Method
System.Void UTF8Deco.SoapIdr::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void c.TimerQu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GratitudeJournal.Form1.resources
GratitudeJournal.Properties.Resources.resources
Clear
[NBF]root.Data
_02
[NBF]root.Data
[NBF]root.Data-preview.png
gUgZtF
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙