Suspicious
Suspect

PE Executable
MD5: 3bf0035077dd6848f02efe34b24468bc
Size: 743.42 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 3bf0035077dd6848f02efe34b24468bc
Sha1 0e95760442717dc595412b7da80eac9e467cd93a
Sha256 833005a44107a2b32181f8a038fb7bc267df6648f0b94dc4a26cd295021b2cb7
Sha384 55eca8391ab9a4ca42b6e8fc50f3b234bc7baab116fed180f363e3058f880164b62dd0beae678c273ea9319001ca5b4d
Sha512 3c08e0acef750cb2149b597c23b827ec0dc87427eabded91c460533d32fb925a2cef001a3afc56e22be245fb78f430fef9b946937070791fbd68fa760ad64b0c
SSDeep 12288:Ag292JaqojL4ezmVBn9fR4Vyp2NvXX9XY/XHSuqLBHVtWTTkBEdT01gTHzelU/4C:A79PqhBn9IceNXiixZVETTkYelS4/vI
TLSH E7F4124D215AD926D49E0BB885A1E2F913746F88BA42E7039ED5BCDF793B78148093C3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SingleQueue.SingleQueue.resources
$this.Icon
[NBF]root.IconData
crc
[NBF]root.Data
Vip.CustomForm.Properties.Resources.resources
FrQn
[NBF]root.Data
[NBF]root.Data-preview.png
Vip.CustomForm.Images.SystemButtons.bmp
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\karadlNUTG\src\obj\Debug\uvrn.pdb
Module Name
uvrn.exe
Full Name
uvrn.exe
EntryPoint
System.Void SingleQueue.Program::Main()
Scope Name
uvrn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
uvrn
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
104
Main Method
System.Void SingleQueue.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SingleQueue.SingleQueue::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SingleQueue.SingleQueue.resources
$this.Icon
[NBF]root.IconData
crc
[NBF]root.Data
Vip.CustomForm.Properties.Resources.resources
FrQn
[NBF]root.Data
[NBF]root.Data-preview.png
Vip.CustomForm.Images.SystemButtons.bmp
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙