Suspicious
Suspect

PE Executable
MD5: 44796d0de9404f45b0e88f3b0a0b00ba
Size: 695.81 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 44796d0de9404f45b0e88f3b0a0b00ba
Sha1 85935e5d7bd9f9d9eaa2fa5a4da6c29f43258925
Sha256 18bcbb69ee3d1e2fd3e6555bd39d384d8030cd333a4aaa924d761a01ff83fdbd
Sha384 d3db774c4de38344a1570e2fa41b1d58b5980975000b64acd310fa9e1cffceaad0cff6d7317f512f41ff0f7cf9d4ce00
Sha512 919dcb9209419eee9c7ad5840bb301c1ce296261d56dff7b06c99816a7dee5f7b9e6bd0202853a4f7b2bde4d8a2e1b4efb6770763ccd6a9d9eb5dfbd5e9f548f
SSDeep 12288:J8Bc6UmKhaRe9FWStYJa1M5lY9gRtxLOQ9MC6dii1f10ZMWOn:Jx6vy59FrY5MCtxn976Ye+ZM/
TLSH 1FE41219270ACB06C0E28FF25932C67427B86EDEE990D347DEE43EDBB07EA585554342
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SystemDashboard.MainForm.resources
SystemDashboard.Properties.Resources.resources
LayerT
[NBF]root.Data
RCVaN
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: IFZQH.pdb
Module Name
IFZQH.exe
Full Name
IFZQH.exe
EntryPoint
System.Void SystemDashboard.Program::Main()
Scope Name
IFZQH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
IFZQH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
184
Main Method
System.Void SystemDashboard.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SystemDashboard.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
IFZQH.exe
Full Name
IFZQH.exe
EntryPoint
System.Void SystemDashboard.Program::Main()
Scope Name
IFZQH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
IFZQH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
184
Main Method
System.Void SystemDashboard.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SystemDashboard.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SystemDashboard.MainForm.resources
SystemDashboard.Properties.Resources.resources
LayerT
[NBF]root.Data
RCVaN
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙