Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 0f391eeaa0e6d7254a623942f2e5a409
Size: 541.7 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 0f391eeaa0e6d7254a623942f2e5a409
Sha1 e98f89976f15cdcbb2956ee7fe1ee5a4c4f086ec
Sha256 2a457ceff9290140853127bd459791a5a17603c116a513da8a499aae112346d5
Sha384 d94e1aaa141db726f866c3e4a0cff398e50c17e157c98de9e5136c78e06cb8b20fb06e1ecfb4eb30e4896486457bb033
Sha512 6a66ed4bf3f3490678b145191ff8f9c53ffaf222835903aac231d5e8e3b0fb5e4993e38e524054a8354668c2d2e5a6be8d248e2866613ed4291f457531e1ffdc
SSDeep 12288:5/pO8vWy+idbeFIOd5vtwNxynUmc1T29oy4:NF3RyhrqNxynUmc5xj
TLSH 45B48B7036AD8963C86586F10520E17537B72ECF642AEAD94ED67CCB3CE4BC12790A17
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
QLDTDD_FPT.AM_Edit.resources
QLDTDD_FPT.Properties.Resources.resources
yoCj
[NBF]root.Data
[NBF]root.Data-preview.png
QLDTDD_FPT.StaffManagementForm.resources
$this.Icon
[NBF]root.IconData
kc
[NBF]root.Data
Name Value
Module Name
osoY.exe
Full Name
osoY.exe
EntryPoint
System.Void QLDTDD_FPT.Program::Main()
Scope Name
osoY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
osoY
Assembly Version
8.5.3.7
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
975
Main Method
System.Void QLDTDD_FPT.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void QLDTDD_FPT.Mainform::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
osoY.exe
Full Name
osoY.exe
EntryPoint
System.Void QLDTDD_FPT.Program::Main()
Scope Name
osoY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
osoY
Assembly Version
8.5.3.7
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
975
Main Method
System.Void QLDTDD_FPT.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void QLDTDD_FPT.Mainform::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
PDB Path PATH
oshuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙