Suspicious
Suspect

PE Executable
MD5: 1a9321be971603958daf61fd9676edea
Size: 721.41 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 1a9321be971603958daf61fd9676edea
Sha1 0817c5d5d62f096171f66e9acdf5c144810e2789
Sha256 7412c73049ad87dbfc8106ce0fc8a03ca2a21d6507fcdb53d96fb2efb8ac1561
Sha384 7d5a3306ef87052621d3eaf2050b72d6653b4a53e700907057bcddd3e63dc6bd9baa53d8e8ecb9c2fb87310834362865
Sha512 a7e6467bdfd99515a63596d28c1069bfbb2b3dc5f9d5dc7c05451bc1f66f989f68bf7e8b1a034a2e0f9b53de262d72306f1710de9fefa99735c85ba16ccb3cf4
SSDeep 12288:C7zIbMIRulEFnR5xsZoX+I/SP8wVujmRYG8Rl0DFj2L8CAke4qiZYRV0Uxc:C7nIY65CGQP8lamG8P0DFjTTeqV0Uq
TLSH 78E412527BD5DA92E4F607F01A70D3760336BECEA420C34BA6EEACEB756475920543C2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RealtekAudio.Properties.Resources.resources
etdR
sik
Name Value
Module Name
yQkl.exe
Full Name
yQkl.exe
EntryPoint
System.Void RealtekAudio.Program::Main()
Scope Name
yQkl.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yQkl
Assembly Version
6.1.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
311
Main Method
System.Void RealtekAudio.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RealtekAudio.VirtualForm81::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
yQkl.exe
Full Name
yQkl.exe
EntryPoint
System.Void RealtekAudio.Program::Main()
Scope Name
yQkl.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
yQkl
Assembly Version
6.1.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
311
Main Method
System.Void RealtekAudio.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RealtekAudio.VirtualForm81::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RealtekAudio.Properties.Resources.resources
etdR
sik
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
1a9321be971603958daf61fd9676edea
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
1a9321be971603958daf61fd9676edea
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙