Suspicious
Suspect

PE Executable
MD5: 0da6ea8aa6fc92b6fbadb1a5c7aac470
Size: 506.2 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 0da6ea8aa6fc92b6fbadb1a5c7aac470
Sha1 f3aa9610e0b40f715e535350c3f5175892d1d119
Sha256 033c55f8f206bede32c03f77eede842650727506dfad0be0aea118b79f9dd922
Sha384 0791dadc57193f861e1cfa0e12bc15e86d96593274878f9f6cfe90234bcbc17f3a188058c9146736ef48dcac73d88f00
Sha512 b1f5588928f51c72ddf018109b8dd8731ea99b70ba1aa038f4094cdbb12b5868b4698eca76b332e205c367937ec976a38c8388057a2ddf708c908c5540fec7e5
SSDeep 6144:UhiIOkmB3TG6v+GHLwvMUtFmPTtu470zIpu3k3MtUnyiwOlkry8CAjE3YX0Uu+m4:UcIOkajGQoG5u406CYyiplkrRj90UxD
TLSH 4BB4015177D5EA13E9FA4BF10930D2761339AFCEB010C34B9AEEACEBB85170424952D6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RealtekAudio.Properties.Resources.resources
HXLy
sik
Name Value
Module Name
Apqb.exe
Full Name
Apqb.exe
EntryPoint
System.Void RealtekAudio.Program::Main()
Scope Name
Apqb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Apqb
Assembly Version
6.1.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
311
Main Method
System.Void RealtekAudio.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RealtekAudio.VirtualForm81::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
Apqb.exe
Full Name
Apqb.exe
EntryPoint
System.Void RealtekAudio.Program::Main()
Scope Name
Apqb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Apqb
Assembly Version
6.1.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
311
Main Method
System.Void RealtekAudio.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RealtekAudio.VirtualForm81::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RealtekAudio.Properties.Resources.resources
HXLy
sik
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
0da6ea8aa6fc92b6fbadb1a5c7aac470
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
0da6ea8aa6fc92b6fbadb1a5c7aac470
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙