Suspicious
Suspect

PE Executable
MD5: 6cfbb7dae5d2c0bbf6a9abbe4d56424e
Size: 741.38 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 6cfbb7dae5d2c0bbf6a9abbe4d56424e
Sha1 1bc72f1f46badb27441fdfca476356d7d4b0e2f2
Sha256 9357bf9a67240b9df693123dfcefe78bd468a313243e9ab7769c60eae161f1ad
Sha384 b5f1a4fac7b536888c33d99858b5892d10b315adcc4f472fae197445fb0317c3f0951c13e8d044167586ca1e9629f22b
Sha512 cab52b76d2795fff2f1b431231db9668e88bc67e610b1f879cb1d8430375b5a5da6f515d0b498535bced2c1c22c01e2acb91e6f748c4101ea52e58c973e0bf60
SSDeep 12288:ag2ORIJaqojL4eLms6YfIeAgZ1aTSD4opOxjZCX6mWGB14ksZVWHD10J6llczYE+:a7OR5qQmX9ja1aQKg6WB1xs+HD10JqC6
TLSH FDF4120A1152D926C07E0BF8D992E5F853749EA9F822E7178FD5BCDB3937788080D2D6
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SingleQueue.SingleQueue.resources
$this.Icon
[NBF]root.IconData
crc
[NBF]root.Data
Vip.CustomForm.Properties.Resources.resources
ebrA
[NBF]root.Data
[NBF]root.Data-preview.png
Vip.CustomForm.Images.SystemButtons.bmp
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\wDRFznsNiA\src\obj\Debug\nGzV.pdb
Module Name
nGzV.exe
Full Name
nGzV.exe
EntryPoint
System.Void SingleQueue.Program::Main()
Scope Name
nGzV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nGzV
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
104
Main Method
System.Void SingleQueue.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SingleQueue.SingleQueue::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SingleQueue.SingleQueue.resources
$this.Icon
[NBF]root.IconData
crc
[NBF]root.Data
Vip.CustomForm.Properties.Resources.resources
ebrA
[NBF]root.Data
[NBF]root.Data-preview.png
Vip.CustomForm.Images.SystemButtons.bmp
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙