Suspicious
Suspect

PE Executable
MD5: 3a00713754955e9bbce32568194f1b81
Size: 821.76 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 3a00713754955e9bbce32568194f1b81
Sha1 1678533483175b824eadd62881c99f70935f1a68
Sha256 068035d7c009e6fec1d2baaad409c8289f1c1bba84c1ba792efe5f963db3f97e
Sha384 f7cf35a7cd41680c6ba0b9aee90b1fe2c32619d4fc8a3f4e114c35ccf2e4327349e7e797ffd425ccc8607e17cc5639a5
Sha512 d4470223dae58c75d6bf82df723bc86c216177341c2d88eaaf2c58f7dcd005b98e610b3f364aa0457e6c6bbb7ae254144e34c1bfe4f14a452f3a3a8662c524f2
SSDeep 12288:kany0Ux9rllGZMnkkPzXv3J0m3YZ8Ge22RWOUccT/wAGiSPhDJjXfvxldRBVMGC6:Ly0U3G6ZPDZSxeB0OUrTNGiSBJDz7MG
TLSH 6805DFAC7214B5EFC4A7C5B2CAA4DD75A6613CAB5317C20780D748AFB94CA939F140F2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Name Value
Module Name
qgUY.exe
Full Name
qgUY.exe
EntryPoint
System.Void ProjectWindowsForms.Program::Main()
Scope Name
qgUY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qgUY
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
527
Main Method
System.Void ProjectWindowsForms.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void ProjectWindowsForms.Program::‌‮‬‪‭‮‫‫‬‍​‎‏​‍‪‎​‬​​‮‬‬​‬‬‍‫‍‫‮()
ldc.i4.0 <null>
call System.Void ProjectWindowsForms.Program::​‭‭‎‍‮‎‎‪‎‎‏‫​‭‬‭​‎‎‬‎‏‮​‮‪‭‪‎‬‮(System.Boolean)
newobj System.Void ProjectWindowsForms.SmartForm13::.ctor()
call System.Void ProjectWindowsForms.Program::‬‌‮‮‏‏‍‮‌‏​‭‎‮‪‭‬‬‭‍‪‭‎‏‮(System.Windows.Forms.Form)
ret <null>
Module Name
qgUY.exe
Full Name
qgUY.exe
EntryPoint
System.Void ProjectWindowsForms.Program::Main()
Scope Name
qgUY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qgUY
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
527
Main Method
System.Void ProjectWindowsForms.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void ProjectWindowsForms.Program::‌‮‬‪‭‮‫‫‬‍​‎‏​‍‪‎​‬​​‮‬‬​‬‬‍‫‍‫‮()
ldc.i4.0 <null>
call System.Void ProjectWindowsForms.Program::​‭‭‎‍‮‎‎‪‎‎‏‫​‭‬‭​‎‎‬‎‏‮​‮‪‭‪‎‬‮(System.Boolean)
newobj System.Void ProjectWindowsForms.SmartForm13::.ctor()
call System.Void ProjectWindowsForms.Program::‬‌‮‮‏‏‍‮‌‏​‭‎‮‪‭‬‬‭‍‪‭‎‏‮(System.Windows.Forms.Form)
ret <null>
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
3a00713754955e9bbce32568194f1b81
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
3a00713754955e9bbce32568194f1b81
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙