Suspicious
Suspect

01f5a219c17b81c5401e6b66f09e891a

PE Executable
MD5: 01f5a219c17b81c5401e6b66f09e891a
Size: 721.42 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 01f5a219c17b81c5401e6b66f09e891a
Sha1 822912918021a5891e857f5e95101f78257ca89c
Sha256 c4133609748071a200e855b6681ce59b918d73fea3a3aa67c7053af38cfda2f2
Sha384 bd33ea3494464d273cd37264ebf7512b3a91539fda9c0154e35a4b18e991cb28c2c8f43ec7916cc8e0237f3f0e8cb8c8
Sha512 e4f38870eda6a246eab9bb262a1707fd6e62bcb1f69b386e875b3e6752fae4625c474ab480080c839849956933ec34ee092348feab7a37591e6fc9278620e57a
SSDeep 12288:fKqOZQ88aX7p1+IZgQW+/pi5FMZNlAYGvq9uEg6pJqgkR:iRQk7p1+IaQNE5FMH+YGy97glH
TLSH 4CE412641A1ADD02D1629F750871E7B41F71AF9AF811C6078FDA3E9FF8B6B602580392
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PrinterQueueManager.Forms.MainForm.resources
PrinterQueueManager.Properties.Resources.resources
IO
[NBF]root.Data
gkUN
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xACC00 size 13832 bytes
Info
PDB Path: BTpN.pdb
Module Name
BTpN.exe
Full Name
BTpN.exe
EntryPoint
System.Void PrinterQueueManager.Program::Main()
Scope Name
BTpN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BTpN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
174
Main Method
System.Void PrinterQueueManager.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PrinterQueueManager.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
BTpN.exe
Full Name
BTpN.exe
EntryPoint
System.Void PrinterQueueManager.Program::Main()
Scope Name
BTpN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BTpN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
174
Main Method
System.Void PrinterQueueManager.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PrinterQueueManager.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PrinterQueueManager.Forms.MainForm.resources
PrinterQueueManager.Properties.Resources.resources
IO
[NBF]root.Data
gkUN
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙