Suspicious
Suspect

PE Executable
MD5: 6cd777ffe145cdd3d86dff6128013aa6
Size: 1.3 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 6cd777ffe145cdd3d86dff6128013aa6
Sha1 6aea060064608778a6266d73a91b3f149e7baec6
Sha256 2944010e5dc27c32e209f1aa2f0e9fb2ba05e90acb0beaccf16622b31389a349
Sha384 62f0674466d86c5b2f16e0895e3abf04aea089682ddab45bf24009dbcfd9b4a3d82bade6ea92745af1e4942c61919971
Sha512 819081cf8df5eff0e0fbfde8a21f9269497d9bd15fa3fa09c0c0513609996d5eb5bdd7d88c15c24063ef325194b4e966fce2fd53ac82585eca5807471725eb84
SSDeep 24576:NrbbXjskG0SmW+ZfYHPr3kNO5UAqa/B60rnV1tVd9oPBTvgOmNUNEbp:NrnXjsIW+ZfsPrUNVAm0xVdiJTvyNUmF
TLSH A25513146615D703D9D69B741AB2F2785BBC6DCAB850E3074FE8ADEFB866B050D08383
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FortuneDisplay.Properties.Resources.resources
Square
[NBF]root.Data
ZAvPL
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x139400 size 13832 bytes
Info
PDB Path: qmUVi.pdb
Module Name
qmUVi.exe
Full Name
qmUVi.exe
EntryPoint
System.Void FortuneDisplay.Program::Main()
Scope Name
qmUVi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qmUVi
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
335
Main Method
System.Void FortuneDisplay.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call FortuneDisplay.FortuneEngine FortuneDisplay.FortuneEngine::get_Instanta()
stloc.0 <null>
newobj System.Void FortuneDisplay.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
qmUVi.exe
Full Name
qmUVi.exe
EntryPoint
System.Void FortuneDisplay.Program::Main()
Scope Name
qmUVi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qmUVi
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
335
Main Method
System.Void FortuneDisplay.Program::Main()
Main IL Instruction Count
12
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call FortuneDisplay.FortuneEngine FortuneDisplay.FortuneEngine::get_Instanta()
stloc.0 <null>
newobj System.Void FortuneDisplay.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FortuneDisplay.Properties.Resources.resources
Square
[NBF]root.Data
ZAvPL
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙