Suspicious
Suspect

PE Executable
MD5: 2385f4fb5b1a1ad95ba4a02125c9331c
Size: 1.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2385f4fb5b1a1ad95ba4a02125c9331c
Sha1 8145a68240d5b659a9acd98d497d6e162f30abe5
Sha256 3dc175bf861340b97aa3de7ba407113cd540fd4b0b4525f5ee1792932f5785f0
Sha384 cbc0bc0bbd328b7e95d5a3b3e7e486f790e7ff45496d513eaea0837d0aefc412c626bf4e75bc91d29c3d79a5b78c1933
Sha512 a954abf457e4ba45b5d7c50c451d959a83b90a011a69b698f9d0c155089f1374790363baeb1a0227dc9e257eb6ebfe0aabf5d11f1e97d69e332bbd8827e7f5eb
SSDeep 24576:VHerIyZk/o4nYU80zOISig68KltUKdli0qSJJSHw:2Iyi/lYU8qOIng6nltLdli0qqUw
TLSH C845F104636BDD03C4A61B7088F1E27407B4AD99E423C2175FE57EEFBA397922A45393
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
yp.NJ.resources
TH6.qHP.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RhythmTracker.Properties.Resources.resources
dexy
[NBF]root.Data
[NBF]root.Data-preview.png
finn
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
pbQn.exe
Full Name
pbQn.exe
EntryPoint
System.Void RP.Qj::A6()
Scope Name
pbQn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pbQn
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
576
Main Method
System.Void RP.Qj::A6()
Main IL Instruction Count
16
Main IL
br IL_000F: nop
call System.Void J0P.P0j::zeX()
br IL_0028: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_001A: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void J0P.P0j::zeX()
nop <null>
ret <null>
nop <null>
newobj System.Void yp.NJ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0026: nop
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
yp.NJ.resources
TH6.qHP.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RhythmTracker.Properties.Resources.resources
dexy
[NBF]root.Data
[NBF]root.Data-preview.png
finn
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙