Suspicious
Suspect

PE Executable
MD5: 3818cf155c79757b444c5775026c2ce0
Size: 689.15 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 3818cf155c79757b444c5775026c2ce0
Sha1 78f8a5b77eb24afc1d71df7d65e975741da948e0
Sha256 3dc467a7a9bcfa23fe34b6dc2932597bb7bbe79108e3d11dbc52b0bd135ef8e2
Sha384 6065e0bf1565a1eaf3e59a743b2d66bbc957b3f80ce5ba1eab3c187bfd046178706ca4c8b0895ebf1242d766d6fbfdaa
Sha512 d2213e27ab4a60597bbacd74a044eab342c093fd43340593387ff8f7154dc5cb42e0d9b4c08aa0fa546fb6a7888fe0976a825d90a957e28dd98877d098d3c799
SSDeep 12288:BU64LAlHPi3yAoN4E8/tWyDT3zesxnqJXlgtIkgLvCoSt0pUyqh27GtJEwz:Fkyj4xresNIdAGqzh6lc
TLSH 86E4F1D03E26AB12CD7547B09A25DDB843651E287011FEEBA9DDBF9737D8201A90CF09
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GänseSpiel.HauptForm.resources
GanseSpiel.Properties.Resources.resources
LastGame
[NBF]root.Data
Slqv
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: qsqH.pdb
Module Name
qsqH.exe
Full Name
qsqH.exe
EntryPoint
System.Void GänseSpiel.Program::Main()
Scope Name
qsqH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qsqH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
133
Main Method
System.Void GänseSpiel.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GänseSpiel.HauptForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
qsqH.exe
Full Name
qsqH.exe
EntryPoint
System.Void GänseSpiel.Program::Main()
Scope Name
qsqH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qsqH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
133
Main Method
System.Void GänseSpiel.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GänseSpiel.HauptForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GänseSpiel.HauptForm.resources
GanseSpiel.Properties.Resources.resources
LastGame
[NBF]root.Data
Slqv
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙