Suspicious
Suspect

PE Executable
MD5: 26ba6cf8b77e313b94259dadfe69c9e1
Size: 1.14 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 26ba6cf8b77e313b94259dadfe69c9e1
Sha1 fd630e45d09afa70fc087289fff2fd3d61856090
Sha256 84a03d4c69389af18a55a569813bd9d02f6c2cee34eea0efb7fe267662bf706e
Sha384 f43f2feb3919141f2ac5d0c53e7412b0707441e313e092106e0f03450efe3eccaff2f599ecd9d7e5136dd844dd82c213
Sha512 1a5c699a9d45d22c8ac9ec5ea79c4f1fd668bf42ad5a090d108d89f360c5b4f952d36cf0c7917f6ba51bf5f25fd02e1d7b0791e1e21e3fc259727d262b2b67c2
SSDeep 24576:PrZnXqyllglglglvRsA9rpYaAZHeTHVrwE9nHGLfWx0/AdzjYMElcRhTexS6K:V6FtpYaApeLVrL9nHafWxh6Wv6K
TLSH 513502DA33A9DD03D27895F3C560E27197F56C9BB920C3C98CDA6CDB71E5B022244A53
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
IndexApp.CalTriangle.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.calBMI.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
IndexApp.FormBSB.resources
iamgeA.ErrorImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmInternetCafe.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmStudentBMI.resources
IndexApp.GoldPriceFrm.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.IndexApp.resources
$this.Icon
[NBF]root.IconData
Ce
[NBF]root.Data
menuStrip1.TrayLocation
IndexApp.Properties.Resources.resources
eCCD
[NBF]root.Data
[NBF]root.Data-preview.png
gold-bars
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x112C00 size 13832 bytes
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\jsloVrreAh\src\obj\Debug\OQkL.pdb
Module Name
OQkL.exe
Full Name
OQkL.exe
EntryPoint
System.Void IndexApp.Program::Main()
Scope Name
OQkL.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OQkL
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
749
Main Method
System.Void IndexApp.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void IndexApp.IndexApp::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
IndexApp.CalTriangle.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.calBMI.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
IndexApp.FormBSB.resources
iamgeA.ErrorImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmInternetCafe.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.FrmStudentBMI.resources
IndexApp.GoldPriceFrm.resources
pictureBox1.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
IndexApp.IndexApp.resources
$this.Icon
[NBF]root.IconData
Ce
[NBF]root.Data
menuStrip1.TrayLocation
IndexApp.Properties.Resources.resources
eCCD
[NBF]root.Data
[NBF]root.Data-preview.png
gold-bars
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙