Suspicious
Suspect

PE Executable
MD5: 19b0b11097e9f1e1128aedbd132a8abc
Size: 923.65 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 19b0b11097e9f1e1128aedbd132a8abc
Sha1 e896a45691f8c13a92df991af742b9a5857ca536
Sha256 aa1badc8a65a7e941f3e9e9ed3e7ab9ff565900904e57bcd8e5428c6b900d522
Sha384 408a9d5904c411b3ab3fb763df7515e27aa7d2c38dcd43b0cfdb2253d299bf329597629c4d2969fb786e86deb83f97b9
Sha512 e9f42a37bd2d5a8127f52874a2b5af4fd2b4dd6dba7abbfe96227e536f97325b0e800021c7c0412020d4ff327b041a28c6e28587b1d2a8533b80653c4124f8f9
SSDeep 24576:2jE4ONgNoxBd5T2hZY3OWdpyGMCsra9TNXRC/omPg:2jEVguxBCgOa9TNhC/bP
TLSH D81512942195E504D1FA3FB828B5E3B487BA3DD9AA32D60B5BE43DDF3C12B0498143E5
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
shu
[NBF]root.Data
uPDJ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: aZqC.pdb
Module Name
aZqC.exe
Full Name
aZqC.exe
EntryPoint
System.Void StudyGuide.Program::Main()
Scope Name
aZqC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
aZqC
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
101
Main Method
System.Void StudyGuide.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void StudyGuide.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
aZqC.exe
Full Name
aZqC.exe
EntryPoint
System.Void StudyGuide.Program::Main()
Scope Name
aZqC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
aZqC
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
101
Main Method
System.Void StudyGuide.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void StudyGuide.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
shu
[NBF]root.Data
uPDJ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙