Suspicious
Suspect

1237c5cf72db8a9697ce7961397b708a

PE Executable
MD5: 1237c5cf72db8a9697ce7961397b708a
Size: 587.26 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 1237c5cf72db8a9697ce7961397b708a
Sha1 4399e44246ca373b896179dbd2e2a342fd9b8dba
Sha256 d65eb6882fa89eefc84f94bed68af0d163d05a0421d9e5346bb5fb7880ca483d
Sha384 852daca2399b7ba01bf413b09afeb094b0c0dc6838a9710553b94b1c4c36db43a74420afa63ea869348565796929f8de
Sha512 8b059dd40ce5dde38df89e1b058e5540320def2783de8a2e18b48f0952778f1ee55dffc2744e2cad99ec323bfb1f006e7e39d226de624c4b0c9e8ded6ca642da
SSDeep 12288:pYhIH8jqBHbRHVFiT9RsWYS/TKejnjfIhcaONpPCEFGiiPTu+:pYhPjuHJi59GSjQhFONpKmGlTu
TLSH 24C42369D71AB232E7C54379886BC70092A48722F1C1DF5B319F1B0F1E46FA5DE86623
PeID
Microsoft Visual C# / Basic .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Yqkqa.Properties.Resources.resources
Kwgofjapq
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Yqkqa.exe
Full Name
Yqkqa.exe
EntryPoint
System.Void Yqkqa.Uuapfugr::Main()
Scope Name
Yqkqa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Yqkqa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
12
Main Method
System.Void Yqkqa.Uuapfugr::Main()
Main IL Instruction Count
19
Main IL
br IL_0040: newobj System.Void Yqkqa.Kxavbmj::.ctor()
nop <null>
ldloc.s V_0
call System.Byte[] Yqkqa.Properties.Tvtytfd::get_Kwgofjapq()
ldsfld System.Byte[] Yqkqa.Iterators.IteratorCompressor::iteratorElements
ldsfld System.Byte[] Yqkqa.Iterators.IteratorCompressor::_IteratorDeciders
ldstr dmdN5OPImV4cbx3wa2q.LnwnngPmOtVINOXKwK3
ldstr dwTPqfePxG
callvirt System.Void Yqkqa.Kxavbmj::Nzwhu(System.Byte[],System.Byte[],System.Byte[],System.String,System.String)
br IL_002B: leave IL_004C
leave IL_004C: ret
pop <null>
br IL_0036: leave IL_004C
leave IL_004C: ret
br IL_004C: ret
newobj System.Void Yqkqa.Kxavbmj::.ctor()
stloc.s V_0
br IL_0005: nop
ret <null>
Module Name
Yqkqa.exe
Full Name
Yqkqa.exe
EntryPoint
System.Void Yqkqa.Uuapfugr::Main()
Scope Name
Yqkqa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Yqkqa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
12
Main Method
System.Void Yqkqa.Uuapfugr::Main()
Main IL Instruction Count
19
Main IL
br IL_0040: newobj System.Void Yqkqa.Kxavbmj::.ctor()
nop <null>
ldloc.s V_0
call System.Byte[] Yqkqa.Properties.Tvtytfd::get_Kwgofjapq()
ldsfld System.Byte[] Yqkqa.Iterators.IteratorCompressor::iteratorElements
ldsfld System.Byte[] Yqkqa.Iterators.IteratorCompressor::_IteratorDeciders
ldstr dmdN5OPImV4cbx3wa2q.LnwnngPmOtVINOXKwK3
ldstr dwTPqfePxG
callvirt System.Void Yqkqa.Kxavbmj::Nzwhu(System.Byte[],System.Byte[],System.Byte[],System.String,System.String)
br IL_002B: leave IL_004C
leave IL_004C: ret
pop <null>
br IL_0036: leave IL_004C
leave IL_004C: ret
br IL_004C: ret
newobj System.Void Yqkqa.Kxavbmj::.ctor()
stloc.s V_0
br IL_0005: nop
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Yqkqa.Properties.Resources.resources
Kwgofjapq
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙