Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: f4e28799fcc062b8b1c0255ec0d4e1cb
Size: 518.14 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 f4e28799fcc062b8b1c0255ec0d4e1cb
Sha1 dce40b45159ed79912034b1487a7464aee61d410
Sha256 99d71c0bc33e95d7a229b32d3f55964f0e0b083fa189fa808b72e340f797b818
Sha384 5d6fbb6b59579feaa38237b0bb0ae11a30eeff35abba8c498f6961c7a50ab653fb2467df5bb52f1851336287a7cff942
Sha512 be3cd09f5e2cee27bac68dc91e1084fc5f52995ec2e4d2e5dd51036873d319ec822f717d3772511d95025094315fd71742099882633ed44b6ef9873bee4ef64d
SSDeep 12288:y1DFaMfpnHaV7iJ/DsVtCtR9mWo3Y8GTWpDKq22TLk:yvp6xiJIwtRm3YLTuDKR2
TLSH F0B41258276BEC12C89A1BF15861D3F542314FCDE023D3079AEAADE7F92D35636282C5
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
POSManager.Properties.Resources.resources
ANQp
[NBF]root.Data
[NBF]root.Data-preview.png
whey
[NBF]root.Data
Name Value
Module Name
OJnI.exe
Full Name
OJnI.exe
EntryPoint
System.Void POSManager.Program::Main()
Scope Name
OJnI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OJnI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
92
Main Method
System.Void POSManager.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void POSManager.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
OJhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙