Suspicious
Suspect

PE Executable
MD5: 03f9b573497f7161f248a01576af66d6
Size: 851.46 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 03f9b573497f7161f248a01576af66d6
Sha1 3cfa68079f2b0107190df43c1c7f1cd8a8407261
Sha256 652a323b76a64c51111ed62e9a6096e5e925b7ee0b1f2700a38be486c9825550
Sha384 86f6a8672232563ed3c0be2d86d35e076cc2efd3e396480554988017168bce9f77a43d8315752ca71924ffe837199fee
Sha512 eb69ca0c418f2535003cd179b956c6fc8bd2fbae8e284fddc950b458d95dc11fb436eb9cb6eaae3120b2bf454989dd57b1c2e119f6ffe0749abb3d10d7a9ed01
SSDeep 12288:PM0r53jPkSEsuPC780YMr3X36d7lN5fiFMBudySmCFP80wrR/SvKFJNhHSYUd9t1:PvjPezP0YMrad735fiaEtPBwEKLS
TLSH D205029C2746D903D9A59B745BB2F6B017BD2DDEE811D3078FE8BDE7B462B848C04212
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RhymeFinder.Properties.Resources.resources
Square
[NBF]root.Data
mtUH
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ParallelLoopStateFlag
Full Name
ParallelLoopStateFlag
EntryPoint
System.Void BufferedStr.Interloc::Main()
Scope Name
ParallelLoopStateFlag
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FWtq
Assembly Version
5.4.2.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
515
Main Method
System.Void BufferedStr.Interloc::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ArgMap.MethodReturnMessageWrap::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ParallelLoopStateFlag
Full Name
ParallelLoopStateFlag
EntryPoint
System.Void BufferedStr.Interloc::Main()
Scope Name
ParallelLoopStateFlag
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FWtq
Assembly Version
5.4.2.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
515
Main Method
System.Void BufferedStr.Interloc::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ArgMap.MethodReturnMessageWrap::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RhymeFinder.Properties.Resources.resources
Square
[NBF]root.Data
mtUH
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙