Suspicious
Suspect

PE Executable
MD5: 3593c9f0050affa76757005e73d05b30
Size: 605.7 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 3593c9f0050affa76757005e73d05b30
Sha1 62d19ad429ff3b6f03588514b7897cf5de2cd6cc
Sha256 4b7f0e5643becb7682232952d7dec1e9c8b52ddcba5dadf9a42a832638f644fd
Sha384 561b88950aa830f67ba2d4fbe17b34b57763a8f75ded05bdc92235f7c39d8603314926d9e98ad412c82d63391cf5f664
Sha512 a343947e8a7744b8dd2c18380a45d2177c4ba51f0229a6c89e6a356690b4d80b536b116ad5c6f7e757450a2273ead9310796db72d778fae98e2864cedf42eaca
SSDeep 12288:h24JriISA92hN8KCpZI7pfocwpsGzo3b4kd:SISA92hNPC41ocVT
TLSH 57D4F151135BDE03D6A247B908C2E3B2A7399D4EB921C70B4FE97DE73D7A74429003A6
Overlay_5b7ffecf.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordleForms.GameOver.resources
WordleForms.WordleForm.resources
$this.Icon
[NBF]root.IconData
True
[NBF]root.Data
statusStrip1.TrayLocation
toolStrip1.TrayLocation
WordleForms.Properties.Resources.resources
help_FILL0_wght300_GRAD0_opsz48
[NBF]root.Data
[NBF]root.Data-preview.png
restart
restart_alt_FILL0_wght400_GRAD0_opsz48
[NBF]root.Data
[NBF]root.Data-preview.png
zHeD
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_5b7ffecf.bin (13830 bytes)
Info
PDB Path: ?
Module Name
QUpL.exe
Full Name
QUpL.exe
EntryPoint
System.Void WordleForms.Program::Main()
Scope Name
QUpL.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QUpL
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
152
Main Method
System.Void WordleForms.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordleForms.WordleForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Overlay_5b7ffecf.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordleForms.GameOver.resources
WordleForms.WordleForm.resources
$this.Icon
[NBF]root.IconData
True
[NBF]root.Data
statusStrip1.TrayLocation
toolStrip1.TrayLocation
WordleForms.Properties.Resources.resources
help_FILL0_wght300_GRAD0_opsz48
[NBF]root.Data
[NBF]root.Data-preview.png
restart
restart_alt_FILL0_wght400_GRAD0_opsz48
[NBF]root.Data
[NBF]root.Data-preview.png
zHeD
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙