Suspicious
Suspect

11d3d98a4476aa70571df8a619f696e6

PE Executable
MD5: 11d3d98a4476aa70571df8a619f696e6
Size: 1.5 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 11d3d98a4476aa70571df8a619f696e6
Sha1 0b01a3b3ba179a220e83522d7e6d7524e7a91946
Sha256 fa086327bf7fa3957e03d5ffcf43fc926aa47fd24b96b479e29bfbccf3becc07
Sha384 208dcb37b1665f8496b2de7fcbf05798a067870b30f60a11ee9a1f1b99313ab63bab6d1d21dcbb51327ebedc22101667
Sha512 2e0180f9e460374c92d90d23150ad1eb888b27dfc83970aadd0451c98e117c9fd06c5c77926aa008b86b5fa4aba54fb6aaea63cdc356c7f89a09de7171fa7df3
SSDeep 24576:npcpvDq4URpr8IEiYdoGMwVPbblGHLCZxEM795ccE0SED90TsXD:uO4UR+iY6Nw9bhGHWzDJfE0NgYD
TLSH C365BE26917CF50AC6F0DA7DF5A0913602ABAD8D1C1CA16D49A47FAE71B1F8C0A03F57
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MazeSolver.Formularios.FormPrincipal.resources
MazeSolver.Properties.Resources.resources
BKjd
[NBF]root.Data
[NBF]root.Data-preview.png
Fast_Tot
[NBF]root.Data
[NBF]root.Data-preview.png
oO
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: qyWj.pdb
Module Name
qyWj.exe
Full Name
qyWj.exe
EntryPoint
System.Void MazeSolver.Program::Main()
Scope Name
qyWj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qyWj
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
319
Main Method
System.Void MazeSolver.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MazeSolver.Formularios.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
qyWj.exe
Full Name
qyWj.exe
EntryPoint
System.Void MazeSolver.Program::Main()
Scope Name
qyWj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qyWj
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
319
Main Method
System.Void MazeSolver.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MazeSolver.Formularios.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MazeSolver.Formularios.FormPrincipal.resources
MazeSolver.Properties.Resources.resources
BKjd
[NBF]root.Data
[NBF]root.Data-preview.png
Fast_Tot
[NBF]root.Data
[NBF]root.Data-preview.png
oO
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙