Suspicious
Suspect

PE Executable
MD5: 61937ddd610f8e4f6dc1d23d0334673a
Size: 746.5 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 61937ddd610f8e4f6dc1d23d0334673a
Sha1 79efb4d3733abfa2c2f21ac032dbb1d088d57432
Sha256 87839de578611fa6fd31f537bf3107e7b7471ee271dc458372ba6efd962f4056
Sha384 51349c8433a5478782aada9c53223bb46f4cb0d43935fa9ddaf17d77cfe98fd1e9e00585a48590dc7906b0e7f68899d2
Sha512 78a06e9b853f21e260f15fa8c4b31d28be195c97b7808f5a7de290efc345478980d7d63ae99bfc729f4ebae7bedd9c4203e802f7772a4ecbfce772cb9017e0f0
SSDeep 12288:Bxtwb/MphRoDaAtLUtZg9/rCyjWliA/Tx5D86DNiD:BxgM/RoWAtLUtar/iQG7LDNi
TLSH 39F42226ABEEC633E16C57B01471D33112792E9AF921E31B8FD9ADAF3949BF04441742
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NotepadPlus.Properties.Resources.resources
OUGU
[NBF]root.Data
[NBF]root.Data-preview.png
PIP
[NBF]root.Data
grass
[NBF]root.Data
[NBF]root.Data-preview.png
grass_tile
[NBF]root.Data
[NBF]root.Data-preview.png
grass_tile_2
[NBF]root.Data
[NBF]root.Data-preview.png
t1
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
Ekqe.exe
Full Name
Ekqe.exe
EntryPoint
System.Void NotepadPlus.Program::Main(System.String[])
Scope Name
Ekqe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ekqe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
203
Main Method
System.Void NotepadPlus.Program::Main(System.String[])
Main IL Instruction Count
52
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NotepadPlus.MainForm::.ctor()
stloc.0 <null>
ldarg.0 <null>
ldlen <null>
ldc.i4.0 <null>
cgt.un <null>
stloc.1 <null>
ldloc.1 <null>
brfalse.s IL_0060: ldloc.0
nop <null>
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
stloc.2 <null>
ldloc.2 <null>
call System.Boolean System.IO.File::Exists(System.String)
stloc.3 <null>
ldloc.3 <null>
brfalse.s IL_005F: nop
nop <null>
nop <null>
ldloc.0 <null>
ldloc.2 <null>
callvirt System.Void NotepadPlus.MainForm::OpenFile(System.String)
nop <null>
nop <null>
leave.s IL_005E: nop
stloc.s ex
nop <null>
ldstr Error opening file: 
ldloc.s ex
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
ldstr NotepadPlus
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_005E: nop
nop <null>
nop <null>
ldloc.0 <null>
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
Ekhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NotepadPlus.Properties.Resources.resources
OUGU
[NBF]root.Data
[NBF]root.Data-preview.png
PIP
[NBF]root.Data
grass
[NBF]root.Data
[NBF]root.Data-preview.png
grass_tile
[NBF]root.Data
[NBF]root.Data-preview.png
grass_tile_2
[NBF]root.Data
[NBF]root.Data-preview.png
t1
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
Ekhuhuhuhu
61937ddd610f8e4f6dc1d23d0334673a
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙