Suspicious
Suspect

37bf2a92bb8d4bcb4bfa8ed52a33e3bc

PE Executable
MD5: 37bf2a92bb8d4bcb4bfa8ed52a33e3bc
Size: 627.71 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 37bf2a92bb8d4bcb4bfa8ed52a33e3bc
Sha1 632e61a3d9ce93033dc4cc39ac15e07060a92c19
Sha256 dc969684c8b2051843d1db4048e2b13e366e769dd8e97a1dc63e1dce0ffcb954
Sha384 fd5701f1bb0926aacb4bc4d746a55da9337ca88f9a1749692318193ce9bafedde92def02f589619938845178646369f5
Sha512 1613d6dc5928899d19a490920c2afb2732392286f2a797dc1abb0be2f87bff0579db2711a3146b9ef392e737bc802610ce4d6ccfdd6e996b704bde7ca354790f
SSDeep 12288:hX0OTMfwHGASC/vNULT/F1jhsqNp4cPau8+7vXhI6X/Wg+D:hgfqGASQNULjnNp4bQ/XugA
TLSH 91D402685B56C506CE450B7C0A32FABC26385EEAE101F6138FE9BEAFBC779465C441C1
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
HeRoSorter.MainForm.resources
$this.Icon
[NBF]root.IconData
Sort1
[NBF]root.Data
HeRoSorter.Properties.Resources.resources
wtfC
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
ZqFd.exe
Full Name
ZqFd.exe
EntryPoint
System.Void HeRoSorter.Program::Main()
Scope Name
ZqFd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ZqFd
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
63
Main Method
System.Void HeRoSorter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HeRoSorter.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
HeRoSorter.MainForm.resources
$this.Icon
[NBF]root.IconData
Sort1
[NBF]root.Data
HeRoSorter.Properties.Resources.resources
wtfC
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙