Suspicious
Suspect

PE Executable
MD5: 322320c44faf19569dc965877e937e00
Size: 833.54 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 322320c44faf19569dc965877e937e00
Sha1 371d2c5f0366d25d2913f5f72261f3f5013af277
Sha256 1df3a2d85ac9bdbfbfae21c062956d5500ae4270bddf5233e72db71527a21585
Sha384 2ed80c49fe06a52c186690f162f4b18b8c17f1ae1f7de3c67c3cbf9e072841ea952bd469390a3289a67e7a2b6e2d1fb8
Sha512 03efd534d9baba563a1823d83e8752a59f915e21ba381cb175c85e7cef396b0a21b64f3b6c9bfc473337e0cfa00ab8792083369cbb99c0f149ad6a5d7744608b
SSDeep 24576:0KskU90dMfK482gDKAvFIr/2r7XUmc5xuc:0KhU9pfF8dFIrOEn+
TLSH 9305BD3032AD9523CAB556F04560D17533A76ECF281AD2DA4ED6BDCB7CE9BC01B84A43
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
QLDTDD_FPT.AM_Edit.resources
QLDTDD_FPT.Properties.Resources.resources
Kext
[NBF]root.Data
[NBF]root.Data-preview.png
QLDTDD_FPT.StaffManagementForm.resources
$this.Icon
[NBF]root.IconData
kc
[NBF]root.Data
Name Value
Module Name
CHKH.exe
Full Name
CHKH.exe
EntryPoint
System.Void QLDTDD_FPT.Program::Main()
Scope Name
CHKH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CHKH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
975
Main Method
System.Void QLDTDD_FPT.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void QLDTDD_FPT.Mainform::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
CHKH.exe
Full Name
CHKH.exe
EntryPoint
System.Void QLDTDD_FPT.Program::Main()
Scope Name
CHKH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CHKH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
975
Main Method
System.Void QLDTDD_FPT.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void QLDTDD_FPT.Mainform::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
PDB Path PATH
CHhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
QLDTDD_FPT.AM_Edit.resources
QLDTDD_FPT.Properties.Resources.resources
Kext
[NBF]root.Data
[NBF]root.Data-preview.png
QLDTDD_FPT.StaffManagementForm.resources
$this.Icon
[NBF]root.IconData
kc
[NBF]root.Data
No malware configuration was found at this point.
PDB Path PATH
CHhuhuhuhu
322320c44faf19569dc965877e937e00
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙