Suspicious
Suspect

PE Executable
MD5: 370997224916f1bd0157297d39031f44
Size: 716.29 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 370997224916f1bd0157297d39031f44
Sha1 61ec9d24b65730cd036b7b2bb494ca764883ffaf
Sha256 888e3ee78f9d77ebe995ee5cd3aaaf1b0c6f1c62e5349fb2666cc8ca8c095c7e
Sha384 f6ef56c9de6a27dc35bfa575a771b396efabefc204c751f63408218a38c27c185d404c3fc69bc8a58a6a827a031c02ff
Sha512 87f2d887f8c6ee6c2bec90df8b69222219b405044b6f74f46019d43cf4185771b90298fa306464a5bda69cf935f4c18343fb3c5c330d135706015d66f5e4c155
SSDeep 12288:WRDxDfH00tgWY7xrAArS5NXm8hN/nTC6ZzHj3S0XUxkep7ukxVbMiNgvmjmk:6NfUfDrS3WkBTCifS5L7ukxVb6Y
TLSH A4E412A06649FA01CC9657F05A64DBFB433E4DCCD411D30BABDEADEBF81A34524A62C1
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PuhonRM.Properties.Resources.resources
RIWH
vgx
PuhonRM.AddItem.resources
PuhonRM.ItemView.resources
btnAdd.Image
Name Value
Module Name
gqjs.exe
Full Name
gqjs.exe
EntryPoint
System.Void PuhonRM.Program::Main()
Scope Name
gqjs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gqjs
Assembly Version
1.6.2010.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
107
Main Method
System.Void PuhonRM.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PuhonRM.ItemView::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
gqjs.exe
Full Name
gqjs.exe
EntryPoint
System.Void PuhonRM.Program::Main()
Scope Name
gqjs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gqjs
Assembly Version
1.6.2010.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
107
Main Method
System.Void PuhonRM.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PuhonRM.ItemView::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PuhonRM.Properties.Resources.resources
RIWH
vgx
PuhonRM.AddItem.resources
PuhonRM.ItemView.resources
btnAdd.Image
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
370997224916f1bd0157297d39031f44
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
370997224916f1bd0157297d39031f44
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙