Suspicious
Suspect

41e0c1c88abedfef27cc9d50e2a5f6fe

PE Executable
MD5: 41e0c1c88abedfef27cc9d50e2a5f6fe
Size: 727.04 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 41e0c1c88abedfef27cc9d50e2a5f6fe
Sha1 577338ecc05df79d813808ee2869238abddc43a6
Sha256 d58f124c5fa8c860d434a1e533bfa7d4fabc252664ddd81a55a871ef7decf237
Sha384 12ca98166fb21fca6ee963f2478f86dab511a2f2ef4133ae8fcb310b2927c9f29fb390629605fde22b152ab3fe868937
Sha512 3e9e247f325a9c132c18d4cb52ec0304a1f9695ed2228a75ccf24cc16c5735774c47245be1b55da83b45e577673014988776bbe22f5d9936ccf563b18f17e758
SSDeep 12288:mRR/fRec0Y4IswOvBWTGLdCP+oPgCriboXqcaKF1SO4UNFEtFVL/QeS28h5ejDTU:MpvswOvBW4d95OnqcV1SOh7EZJ1MejDV
TLSH 21F40224215ADF03C4A30FF81A60E1B467B8DE9DA525D35B5FD63DEFB86AB811900387
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RM_Colocar.FrmMenu.resources
$this.Icon
[NBF]root.IconData
Capo
[NBF]root.Data
menuStrip1.TrayLocation
RM_Colocar.Properties.Resources.resources
kgga
[NBF]root.Data
[NBF]root.Data-preview.png
x
[NBF]root.Data
[NBF]root.Data-preview.png
RM_Colocar.Views.FrmCaixa.resources
RM_Colocar.Views.FrmCidades.resources
btnAlterar.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnCancelar.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnExcluir.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnIncluir.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnPesquisa.Image
[NBF]root.Data
[NBF]root.Data-preview.png
RM_Colocar.Views.FrmClientes.resources
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\ZByFEkEpHt\src\obj\Debug\YYQn.pdb
Module Name
YYQn.exe
Full Name
YYQn.exe
EntryPoint
System.Void RM_Colocar.Program::Main()
Scope Name
YYQn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YYQn
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
234
Main Method
System.Void RM_Colocar.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RM_Colocar.FrmMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
YYQn.exe
Full Name
YYQn.exe
EntryPoint
System.Void RM_Colocar.Program::Main()
Scope Name
YYQn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YYQn
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
234
Main Method
System.Void RM_Colocar.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RM_Colocar.FrmMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RM_Colocar.FrmMenu.resources
$this.Icon
[NBF]root.IconData
Capo
[NBF]root.Data
menuStrip1.TrayLocation
RM_Colocar.Properties.Resources.resources
kgga
[NBF]root.Data
[NBF]root.Data-preview.png
x
[NBF]root.Data
[NBF]root.Data-preview.png
RM_Colocar.Views.FrmCaixa.resources
RM_Colocar.Views.FrmCidades.resources
btnAlterar.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnCancelar.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnExcluir.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnIncluir.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnPesquisa.Image
[NBF]root.Data
[NBF]root.Data-preview.png
RM_Colocar.Views.FrmClientes.resources
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙