Suspicious
Suspect

0542ade50c2fba4ec61499340cc21884

PE Executable
MD5: 0542ade50c2fba4ec61499340cc21884
Size: 1.08 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 0542ade50c2fba4ec61499340cc21884
Sha1 ab332f0b1b72cae0727b85d96c6a0be0fd1e1b93
Sha256 04e293d3a35fc2a8a1c90f28fa4d1c92412a04757035972fd49f47de0e5e5a9a
Sha384 8dbc6353ce40a34f9bf2688e8562c00b920efb530eb6b2c78fe38f1b1e7608ee6a06dc904c4c51f4407460affcfbf803
Sha512 33c83b438dc2b748b7dbc466beb575d02d5fb0e516d487a7324c553f841a75c8ccc5a0cf48b03f01b6819eb84a0f871ae753bad5daef1433d15d42ccc6535d02
SSDeep 24576:8YYawfiZKUcBnCYoz49xjMnFtlB/LApclnWtALYKdjU2PwCKG2W1:8YYawq8UcBnCY+dzwQnWtALYqU2YA
TLSH 4F351228F729D513C98787710835E7B502B05DECA521C39B9BF9FDEB3869A0A3C1D291
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
NeuralCarSandbox.UI.EvolutionDashboard.resources
$this.Icon
[NBF]root.IconData
VIN
[NBF]root.Data
NeuralCarSandbox.Properties.Resources.resources
ISaP
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
rIqf.exe
Full Name
rIqf.exe
EntryPoint
System.Void NeuralCarSandbox.Program::Main()
Scope Name
rIqf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rIqf
Assembly Version
3.8.5.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
115
Main Method
System.Void NeuralCarSandbox.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void NeuralCarSandbox.UI.EvolutionDashboard::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
NeuralCarSandbox.UI.EvolutionDashboard.resources
$this.Icon
[NBF]root.IconData
VIN
[NBF]root.Data
NeuralCarSandbox.Properties.Resources.resources
ISaP
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙