Suspicious
Suspect

51b570a6b0467d65a55159787efeaebe

PE Executable
MD5: 51b570a6b0467d65a55159787efeaebe
Size: 761.86 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 51b570a6b0467d65a55159787efeaebe
Sha1 be6cd96b8ad9956e8747997bab0304506f924a32
Sha256 e0b121bb61726c3dd38b608de99e46a9842177e9ffdd20611e1725e4c0d77702
Sha384 909d7f01703d1063a689a57636748dda157d0813d090f349d2bcf6c043bf5f8c1854bdd4b0aa33e97c80a1d100daea99
Sha512 625811cf7a171486244c1f9a8a2a899281ccc6176cc0ba297407f7ecafc73e6c45cabecdf5c3310c055d0aada216d48dc33102ee5e2d9596723722da276ef9f2
SSDeep 12288:0X2SelyAFtKRz34976C/UK7Y5YtHeUmwQi5TJIGyCrxqq+yEqAgu+T5PoEZUvVE0:0Ze4CtKpE76CsKJtyeTJIHix57Egu+TS
TLSH 99F412656A8AEB01C8E1C7F40362D37953B54E9DE023D3539FEA7CEB7D9AB410944283
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Dijkstra.Form1.resources
$this.Icon
[NBF]root.IconData
M3
[NBF]root.Data
menuStrip1.TrayLocation
Dijkstra.FrmPercorsoMinimo.resources
Dijkstra.Properties.Resources.resources
aquamarine-circle
[NBF]root.Data
[NBF]root.Data-preview.png
red-circle
[NBF]root.Data
[NBF]root.Data-preview.png
sRfA
[NBF]root.Data
[NBF]root.Data-preview.png
yellow-circle
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
QKPv.exe
Full Name
QKPv.exe
EntryPoint
System.Void Dijkstra.Program::Main()
Scope Name
QKPv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QKPv
Assembly Version
3.2.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
109
Main Method
System.Void Dijkstra.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Dijkstra.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
QKPv.exe
Full Name
QKPv.exe
EntryPoint
System.Void Dijkstra.Program::Main()
Scope Name
QKPv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QKPv
Assembly Version
3.2.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
109
Main Method
System.Void Dijkstra.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Dijkstra.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Embedded Resources UNKNWOWNsuspect
7huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Dijkstra.Form1.resources
$this.Icon
[NBF]root.IconData
M3
[NBF]root.Data
menuStrip1.TrayLocation
Dijkstra.FrmPercorsoMinimo.resources
Dijkstra.Properties.Resources.resources
aquamarine-circle
[NBF]root.Data
[NBF]root.Data-preview.png
red-circle
[NBF]root.Data
[NBF]root.Data-preview.png
sRfA
[NBF]root.Data
[NBF]root.Data-preview.png
yellow-circle
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
51b570a6b0467d65a55159787efeaebe
Embedded Resources UNKNWOWNsuspect
7huhuhuhu
51b570a6b0467d65a55159787efeaebe
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
51b570a6b0467d65a55159787efeaebe
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙