Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 2385f4fb5b1a1ad95ba4a02125c9331c
Size: 1.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2385f4fb5b1a1ad95ba4a02125c9331c
Sha1 8145a68240d5b659a9acd98d497d6e162f30abe5
Sha256 3dc175bf861340b97aa3de7ba407113cd540fd4b0b4525f5ee1792932f5785f0
Sha384 cbc0bc0bbd328b7e95d5a3b3e7e486f790e7ff45496d513eaea0837d0aefc412c626bf4e75bc91d29c3d79a5b78c1933
Sha512 a954abf457e4ba45b5d7c50c451d959a83b90a011a69b698f9d0c155089f1374790363baeb1a0227dc9e257eb6ebfe0aabf5d11f1e97d69e332bbd8827e7f5eb
SSDeep 24576:VHerIyZk/o4nYU80zOISig68KltUKdli0qSJJSHw:2Iyi/lYU8qOIng6nltLdli0qqUw
TLSH C845F104636BDD03C4A61B7088F1E27407B4AD99E423C2175FE57EEFBA397922A45393
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
yp.NJ.resources
TH6.qHP.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RhythmTracker.Properties.Resources.resources
dexy
[NBF]root.Data
[NBF]root.Data-preview.png
finn
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
pbQn.exe
Full Name
pbQn.exe
EntryPoint
System.Void RP.Qj::A6()
Scope Name
pbQn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pbQn
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
576
Main Method
System.Void RP.Qj::A6()
Main IL Instruction Count
16
Main IL
br IL_000F: nop
call System.Void J0P.P0j::zeX()
br IL_0028: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_001A: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void J0P.P0j::zeX()
nop <null>
ret <null>
nop <null>
newobj System.Void yp.NJ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0026: nop
An error has occurred. This application may no longer respond until reloaded. Reload 🗙