Suspicious
Suspect

53d8954358604b11a128241b71df7278

PE Executable
MD5: 53d8954358604b11a128241b71df7278
Size: 859.65 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 53d8954358604b11a128241b71df7278
Sha1 140b0ecaf2a6545606bf678e6d8acda6225f09dd
Sha256 a462c4e403c7daccff53007c275c2e323d860fea97a5e2ecf0bd055ddfefe260
Sha384 1f71b7d7ffd054f4b6eae75cb123a7b78d9b7799e73679c91971ca4117796ac9c150a5e6f5472e8eb123c30aa5cade12
Sha512 d7a913c033df2ad2c14ec1ffd0ad74748e7436fba2cb7750ce0fc59dbe3da2d8df6f5b0d0e30d9ed159758570bf1327772dd63567104512c4f4ac38fc8bf7486
SSDeep 24576:F5daHW1mZ5ekbAUxKkJjWlFdK9wRGqC7I:ZvmZxbAkKkJql3IwO7I
TLSH B705D01822A49E02E03D53798971E27423F16C5B9517E70ADFD8FCEB3E21BE1590A687
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QuantumAnalyzer.ShellExtension.bt_.resources
$this.Icon
[NBF]root.IconData
GM
[NBF]root.Data
QuantumAnalyzer.ShellExtension.Form2.resources
QuantumAnalyzer.ShellExtension.Properties.Resources.resources
nHYL
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Module Name
cwfN.exe
Full Name
cwfN.exe
EntryPoint
System.Void QuantumAnalyzer.ShellExtension.A::Main()
Scope Name
cwfN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
cwfN
Assembly Version
0.0.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
1601
Info
PE Detect: PeReader OK (file layout)
Main Method
System.Void QuantumAnalyzer.ShellExtension.A::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void QuantumAnalyzer.ShellExtension.bt_::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Info
PDB Path: ?
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QuantumAnalyzer.ShellExtension.bt_.resources
$this.Icon
[NBF]root.IconData
GM
[NBF]root.Data
QuantumAnalyzer.ShellExtension.Form2.resources
QuantumAnalyzer.ShellExtension.Properties.Resources.resources
nHYL
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙