Suspicious
Suspect

465121f65e9e8865b36cf0891b976b82

PE Executable
|
MD5: 465121f65e9e8865b36cf0891b976b82
|
Size: 731.65 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
465121f65e9e8865b36cf0891b976b82
Sha1
511517c6aa102d31e64428f14c5c30685c9b84c2
Sha256
be3b41c810133c52469f01114284c66d96cbbeafefd4d1055f3202d0564826be
Sha384
2801cf73495f1eb8879f2241d3dba7c1c2309ca0f6f2b09256e80c2f5a8eed9ca059c5c23ae71a3e90457bb9a27fd7a2
Sha512
44f6185d8668094262a6ad41f1904fedca0eb7da36e369316c4da4b6b362de4ca009f0f8525f570b806b739286d8bf651605e37329419b457f7d4fe425d5e17d
SSDeep
12288:GpO0M39ysCCZ3MwIU4YBwi4Gwg5PFDfqc2R4E3kzrTlwrRophu9:Gk0M3QtCZ3MwIHqwizR5JINkzr+lops9
TLSH
B4F412247704EE12DACA7FF45861D37653749E8EB403D3078EEC6C9BBE26B562448392

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NetworkMonitor.Properties.Resources.resources
cgi
[NBF]root.Data
wNlz
[NBF]root.Data
[NBF]root.Data-preview.png
Informations
Name
Value
Module Name

zqBg.exe

Full Name

zqBg.exe

EntryPoint

System.Void NetworkMonitor.Program::Main()

Scope Name

zqBg.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

zqBg

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

113

Main Method

System.Void NetworkMonitor.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void NetworkMonitor.Forms.NetworkUtilitiesForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Module Name

zqBg.exe

Full Name

zqBg.exe

EntryPoint

System.Void NetworkMonitor.Program::Main()

Scope Name

zqBg.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

zqBg

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

113

Main Method

System.Void NetworkMonitor.Program::Main()

Main IL Instruction Count

10

Main IL

nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.0 <null> call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean) nop <null> newobj System.Void NetworkMonitor.Forms.NetworkUtilitiesForm::.ctor() call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> ret <null>

Artefacts
Name
Value
PDB Path

zqBg.pdb

465121f65e9e8865b36cf0891b976b82 (731.65 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NetworkMonitor.Properties.Resources.resources
cgi
[NBF]root.Data
wNlz
[NBF]root.Data
[NBF]root.Data-preview.png
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
PDB Path

zqBg.pdb

465121f65e9e8865b36cf0891b976b82

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙