Suspicious
Suspect

41e0c1c88abedfef27cc9d50e2a5f6fe

Share on LinkedIn
Print
PE Executable
MD5: 41e0c1c88abedfef27cc9d50e2a5f6fe
Size: 727.04 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 41e0c1c88abedfef27cc9d50e2a5f6fe
Sha1 577338ecc05df79d813808ee2869238abddc43a6
Sha256 d58f124c5fa8c860d434a1e533bfa7d4fabc252664ddd81a55a871ef7decf237
Sha384 12ca98166fb21fca6ee963f2478f86dab511a2f2ef4133ae8fcb310b2927c9f29fb390629605fde22b152ab3fe868937
Sha512 3e9e247f325a9c132c18d4cb52ec0304a1f9695ed2228a75ccf24cc16c5735774c47245be1b55da83b45e577673014988776bbe22f5d9936ccf563b18f17e758
SSDeep 12288:mRR/fRec0Y4IswOvBWTGLdCP+oPgCriboXqcaKF1SO4UNFEtFVL/QeS28h5ejDTU:MpvswOvBW4d95OnqcV1SOh7EZJ1MejDV
TLSH 21F40224215ADF03C4A30FF81A60E1B467B8DE9DA525D35B5FD63DEFB86AB811900387
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RM_Colocar.FrmMenu.resources
$this.Icon
[NBF]root.IconData
Capo
[NBF]root.Data
menuStrip1.TrayLocation
RM_Colocar.Properties.Resources.resources
kgga
[NBF]root.Data
[NBF]root.Data-preview.png
x
[NBF]root.Data
[NBF]root.Data-preview.png
RM_Colocar.Views.FrmCaixa.resources
RM_Colocar.Views.FrmCidades.resources
btnAlterar.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnCancelar.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnExcluir.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnIncluir.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btnPesquisa.Image
[NBF]root.Data
[NBF]root.Data-preview.png
RM_Colocar.Views.FrmClientes.resources
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\ZByFEkEpHt\src\obj\Debug\YYQn.pdb
Module Name
YYQn.exe
Full Name
YYQn.exe
EntryPoint
System.Void RM_Colocar.Program::Main()
Scope Name
YYQn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YYQn
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
234
Main Method
System.Void RM_Colocar.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RM_Colocar.FrmMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
YYQn.exe
Full Name
YYQn.exe
EntryPoint
System.Void RM_Colocar.Program::Main()
Scope Name
YYQn.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YYQn
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
234
Main Method
System.Void RM_Colocar.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RM_Colocar.FrmMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙