Suspect
PE Executable
MD5: 2385f4fb5b1a1ad95ba4a02125c9331c
Size: 1.27 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 2385f4fb5b1a1ad95ba4a02125c9331c |
| Sha1 | 8145a68240d5b659a9acd98d497d6e162f30abe5 |
| Sha256 | 3dc175bf861340b97aa3de7ba407113cd540fd4b0b4525f5ee1792932f5785f0 |
| Sha384 | cbc0bc0bbd328b7e95d5a3b3e7e486f790e7ff45496d513eaea0837d0aefc412c626bf4e75bc91d29c3d79a5b78c1933 |
| Sha512 | a954abf457e4ba45b5d7c50c451d959a83b90a011a69b698f9d0c155089f1374790363baeb1a0227dc9e257eb6ebfe0aabf5d11f1e97d69e332bbd8827e7f5eb |
| SSDeep | 24576:VHerIyZk/o4nYU80zOISig68KltUKdli0qSJJSHw:2Iyi/lYU8qOIng6nltLdli0qqUw |
| TLSH | C845F104636BDD03C4A61B7088F1E27407B4AD99E423C2175FE57EEFBA397922A45393 |
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | pbQn.exe |
| Full Name | pbQn.exe |
| EntryPoint | System.Void RP.Qj::A6() |
| Scope Name | pbQn.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | pbQn |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 576 |
| Main Method | System.Void RP.Qj::A6() |
| Main IL Instruction Count | 16 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.