Suspicious
Suspect

PE Executable
MD5: 06e58d08008d13d9d5a938a4cd35ef54
Size: 1.32 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 06e58d08008d13d9d5a938a4cd35ef54
Sha1 c73730175b28e6b7ee291801f29b451d655b134d
Sha256 58cce80d5bbdc0c8e5aa1ca98e9113c8f997c96435fb7206978e5b1bea4e0197
Sha384 e72994d7f5138a5e4d3fd1aae65db1fecadc348fe2d95c043db2a6b5634fd25225a3f5ee8c5d3f144da4a09a58853a5a
Sha512 0b9b01bf1757929dc6021adf6a0143b1cbb349a6ad19c6fd3d11bab0362a5bdab9e8f28aaa15bf2629612b1d885ef4f7ea46c41136aa00786961041dc930a530
SSDeep 24576:9E29maEhOhBTIrH+KZjhWgLF0qp0350ww/22QttDt9eBz23HUc2h:W2U3QAe4jhn0quhw/22YtJQh23t2h
TLSH F3551279361BDE12C5A01BB089A0D2711BB16E1DB810E267FFE57EEFB579B052908313
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BitTools.Forms.MainLauncher.resources
BitTools.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
VIttDP
[NBF]root.Data
[NBF]root.Data-preview.png
xfi
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x13DE00 size 13832 bytes
Info
PDB Path: QoFNKj.pdb
Module Name
QoFNKj.exe
Full Name
QoFNKj.exe
EntryPoint
System.Void BitTools.Program::Main()
Scope Name
QoFNKj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QoFNKj
Assembly Version
201.502.607.709
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
456
Main Method
System.Void BitTools.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BitTools.Forms.MainLauncher::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
QoFNKj.exe
Full Name
QoFNKj.exe
EntryPoint
System.Void BitTools.Program::Main()
Scope Name
QoFNKj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QoFNKj
Assembly Version
201.502.607.709
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
456
Main Method
System.Void BitTools.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void BitTools.Forms.MainLauncher::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BitTools.Forms.MainLauncher.resources
BitTools.Properties.Resources.resources
Bullet00
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet02
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet03
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet04
[NBF]root.Data
[NBF]root.Data-preview.png
Bullet05
[NBF]root.Data
[NBF]root.Data-preview.png
VIttDP
[NBF]root.Data
[NBF]root.Data-preview.png
xfi
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙