Suspicious
Suspect

02ecaeec70c09fcb7728ab2cdfb99fe0

PE Executable
MD5: 02ecaeec70c09fcb7728ab2cdfb99fe0
Size: 638.46 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 02ecaeec70c09fcb7728ab2cdfb99fe0
Sha1 7fe3127c273a81161f564587de31d62840312375
Sha256 e6278519074f69f35442584cd11ceafbc90f84e9cc9bb8a542b1c39cf253f5bb
Sha384 14c8957c878a250905c6dd9f6a4b22a0c94877b700b65b641dc911bf89440b4619f1a0712daa857a95d867d493f2e090
Sha512 b8fb9d7955e4833d3cd72c7da9c8dfbbb665bd5e7a3250567dc9113f5c86c6896c0031ff5d545a0ddf4fb15d284fe0e1537e40e710f685aabefc74a827cc137f
SSDeep 12288:nRYS0m9hhQ/ULkDoMHNl10ZVeb5dU8NpLGlg4+mqBFEIgcbBPMwokbO:RXnoULkDoM3bo8vqll+mqBBkwokb
TLSH F2D4CF243BF4893BE99EA8B86509D1301375EE1AD5C2D3C11CD8B8D737B17D09AE294B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
 .resources
 .resources
$this.Icon
[NBF]root.IconData
 .resources
$this.Icon
[NBF]root.IconData
DeviceMeasures.Properties.Resources.resources
LPP
[NBF]root.Data
XFRt
[NBF]root.Data
[NBF]root.Data-preview.png
settings
[NBF]root.Data
[NBF]root.Data-preview.png
smile
[NBF]root.Data
[NBF]root.Data-preview.png
         
Name Value
Module Name
aQUi.exe
Full Name
aQUi.exe
EntryPoint
System.Void  ::()
Scope Name
aQUi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
aQUi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
0
Main Method
System.Void  ::()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void  ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
aQUi.exe
Full Name
aQUi.exe
EntryPoint
System.Void  ::()
Scope Name
aQUi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
aQUi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
0
Main Method
System.Void  ::()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void  ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
 .resources
 .resources
$this.Icon
[NBF]root.IconData
 .resources
$this.Icon
[NBF]root.IconData
DeviceMeasures.Properties.Resources.resources
LPP
[NBF]root.Data
XFRt
[NBF]root.Data
[NBF]root.Data-preview.png
settings
[NBF]root.Data
[NBF]root.Data-preview.png
smile
[NBF]root.Data
[NBF]root.Data-preview.png
         
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙