Suspicious
Suspect

PE Executable
MD5: 1206bd5b26944d2eaa4eb51d0bafecd2
Size: 726.02 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 1206bd5b26944d2eaa4eb51d0bafecd2
Sha1 05a3ea1b476aad6efc5f71c1a7baf9d1aae5c6e0
Sha256 68ef29d9bd6e88b4fda357fa69b156376a0a611d287e909285bebbc0d6afc059
Sha384 fee36716b95d911589155a29ddbfc81d0a9a17c0a65bf12e1003287b3ccb2b09668d457f775d986b6919872ae508d4d2
Sha512 f1ec470f466915bc48a742eecc5bf38757e7dfa2488a30f60c3cfaad640292e998267852d78e35d4374f5215b0fbaf9be0fefae3b6b952778e56bc8343d52a5b
SSDeep 12288:60OW2o4mbtbT986YCWiUBT8e4F9fEiW3Vj6LckTutmH2HEvI+fkF5Wr8RChGoPxf:p4mRh8RCu8a6wkuLJWrfbLQe/
TLSH 7CF4125C2357DA23E2A117F44CF5E37862B56E9AA401C7478BD9FEEB39297003990393
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorSchemeGenerator.ExportForm.resources
ColorSchemeGenerator.Properties.Resources.resources
KS
[NBF]root.Data
PDqg
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: qkvC.pdb
Module Name
qkvC.exe
Full Name
qkvC.exe
EntryPoint
System.Void ColorSchemeGenerator.Program::Main()
Scope Name
qkvC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qkvC
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
168
Main Method
System.Void ColorSchemeGenerator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ColorSchemeGenerator.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorSchemeGenerator.ExportForm.resources
ColorSchemeGenerator.Properties.Resources.resources
KS
[NBF]root.Data
PDqg
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙