Suspicious
Suspect

PE Executable
MD5: 0d93539d189b73b1cb1c07dd6c24294a
Size: 963.58 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0d93539d189b73b1cb1c07dd6c24294a
Sha1 a7a658b3d29d65529fa25aa3613cd08c553290a7
Sha256 3021e7589fef17cce2d2dac8424ecc68a61d84cf25762c4caad209aa0a51e68a
Sha384 9677a40e1b8a84067141ceb1cdb55dbd8768d49deac5ae742bf43a723525e4041cae6127f57b78c62c5909976aceef9f
Sha512 1e508bb8fce1d0b97eeb640e4293b7215bb475848327b87f299d8a7992cd03209a181f86f8dd12fade01f595963873d36ea1cb67709d88918d0db7be22c5ec99
SSDeep 24576:Qjbpa7R/4PxkwDYtfI8oO6wUubTrtXHWYOA8MJoswG:6wuPxk4yKb0/d23oOsL
TLSH 3C25125695538D06D0E70BBD27BAC07A22356FCEA826C71F4FD27C9738B3786168A701
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETPrivate EXE Protector V2.30-V2.3X -> SetiSoft Team
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
Name Value
Module Name
oXkq.exe
Full Name
oXkq.exe
EntryPoint
System.Void WindowsFormsApp51.Program::Main()
Scope Name
oXkq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oXkq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
218
Main Method
System.Void WindowsFormsApp51.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WindowsFormsApp51.StudentsManagerForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
oXkq.exe
Full Name
oXkq.exe
EntryPoint
System.Void WindowsFormsApp51.Program::Main()
Scope Name
oXkq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oXkq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
218
Main Method
System.Void WindowsFormsApp51.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WindowsFormsApp51.StudentsManagerForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
0d93539d189b73b1cb1c07dd6c24294a
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
0d93539d189b73b1cb1c07dd6c24294a
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙