Suspicious
Suspect

PE Executable
MD5: 63ebe517cbc6b21f05987509141b4a7c
Size: 734.21 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 63ebe517cbc6b21f05987509141b4a7c
Sha1 b41db01a91b674a28a1ea0cc5a2e49ad68d02afc
Sha256 75e54e1163e476f84f0659124fe3d3c436ca2d1c84e7b17adf3b69366e20b18a
Sha384 8982206f6da63d7545796b166c617ac3874f200b9a7fddc0daf841be618f73e99a07bb98190875b79aa2b694f1758123
Sha512 dcf45d9cfa4703075b15571cfc0e45282a1a04ddf7d8476e1a3cf6a402cb8f3bd14b69cfe715ea15a61d03d1c0bdb4226d835dabba1a5e956e4aeabc8f02f82c
SSDeep 12288:vamRsA9tL7xfQslb01cH+6TxLS+OOVBtqgZyzV1p7OfcSgz1idxQF6ReLm:5RsA9h7Z14+e6Txu+OOVj0J1lwjsid2/
TLSH 2EF4125113AAD903E0A207B98962E3B813784ECEB111D35B8AFDBCD77D3A7107995363
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PassGenerator.Forms.MainForm.resources
PassGenerator.Properties.Resources.resources
Ce
[NBF]root.Data
TGZH
[NBF]root.Data
[NBF]root.Data-preview.png
gold_bars
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: cGQi.pdb
Module Name
cGQi.exe
Full Name
cGQi.exe
EntryPoint
System.Void PassGenerator.Program::Main()
Scope Name
cGQi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
cGQi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
99
Main Method
System.Void PassGenerator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PassGenerator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PassGenerator.Forms.MainForm.resources
PassGenerator.Properties.Resources.resources
Ce
[NBF]root.Data
TGZH
[NBF]root.Data
[NBF]root.Data-preview.png
gold_bars
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙