Suspicious
Suspect

39084089a3fc8d917f35879cf156ab87

PE Executable
MD5: 39084089a3fc8d917f35879cf156ab87
Size: 1.58 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 39084089a3fc8d917f35879cf156ab87
Sha1 75705936389d52131d0bc595a961e30ba3cd6459
Sha256 d1f7d720167c082a602177134934c8669fa9fa3110e50a2f03a336a78357abcd
Sha384 826d0e4c3544c74aee084fc4664554c90ea8510294191e76feaeafef19b71886dd0951e5d8ba0c86890aecff21e177c6
Sha512 d7f1222ffd00b2e640ed819c886e2c31c65d59083bd41ea09633d8e83223966f18f9fc858ae437cfc8142007aacf124b3e7823623d94fbe8ef836449389d6ed5
SSDeep 24576:Du6XApA02tFHWj8HY0ZCzcHu4LEBDNO4KKx1HYyiFJJbRMT+xpnZ:wpJ24uTCzcO4LEfeSiFJJbCT+xpnZ
TLSH 84752316A64BDA03D66447B84DB5C3B9F3AE2FD9F112D2079EC97DCBB81964038413A3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorConvert.MainForm.resources
ColorConvert.Properties.Resources.resources
KS
[NBF]root.Data
xcnW
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: qstq.pdb
Module Name
qstq.exe
Full Name
qstq.exe
EntryPoint
System.Void ColorConvert.Program::Main()
Scope Name
qstq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qstq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
140
Main Method
System.Void ColorConvert.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ColorConvert.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorConvert.MainForm.resources
ColorConvert.Properties.Resources.resources
KS
[NBF]root.Data
xcnW
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙