Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: f447d465aeb908aa17e0e51982949ce0
Size: 757.76 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 f447d465aeb908aa17e0e51982949ce0
Sha1 17ae185f16a88fb53c33166ed2cad198decacb3b
Sha256 a172deb94ea7c05df19865326d5b50e5e2b594f32e9f417b8f5544e2cf98cbcc
Sha384 f9dd46a367ebec7fc9b4b6aa4302532486d85d9e81230452c7514c31ed9bf2654f1962f6c0254ee40c1ea8171274af57
Sha512 ed05ec802ed1cedf50c1229fe4d5cc115f40ba6b10d8c2c0d47d3017d20f737ba36f2369893c7be9d34c99ddb3155800410a2f6092eed6b5e0c9dbe2c34f5f33
SSDeep 12288:AfznnfwkY3zFNZr6QwI/v6cnPn+I/B2n36rARRfsl3DASlaPhC5bGLuDwcwNVa2N:Abnnfwkmr6Q9vVP5Be36rGREhDAS6hyn
TLSH 4CF41215275ACE03D4AA0BF04D72E37407B4AE8A6814D30B9EF6FDE338727415D963A6
PeID
Armadillo v4.x
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SmartNetworkAnalyzer.Forms.MainForm.resources
SmartNetworkAnalyzer.Properties.Resources.resources
greyder
[NBF]root.Data
ncp
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
VRJ.exe
Full Name
VRJ.exe
EntryPoint
System.Void SmartNetworkAnalyzer.Program::Main()
Scope Name
VRJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VRJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
243
Main Method
System.Void SmartNetworkAnalyzer.Program::Main()
Main IL Instruction Count
26
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
nop <null>
newobj System.Void SmartNetworkAnalyzer.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0040: ret
stloc.0 <null>
nop <null>
ldstr An unexpected error occurred: {0}

The application will now close.
ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
call System.String System.String::Format(System.String,System.Object)
ldstr Fatal Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0040: ret
ret <null>
PDB Path PATH
VRhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙