Suspicious
Suspect

PE Executable
MD5: 6df388e9f6987af7e9e7e636a196491e
Size: 1.21 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 6df388e9f6987af7e9e7e636a196491e
Sha1 190eeddd325bf2c70f1d3ba69453de0eed29eb04
Sha256 a0f64f3bb700ae9170efc662301196fe5d635dbbc72985164537a87602d6bf16
Sha384 46f939f3766f53e851ae5349a33c8aa3f01626c7d302b1e7ed4fe66d738aea95d6ad7a2a791747e806d485abfdcf3aa5
Sha512 8159cf377c8c22ad52c7bcca588a6648456ee1ac46a517d6a41420c4e764b0f8c68d40777eb0a090ad6218ea14a380ea8e5c941e7e2bfde0729775fbb4f7b26e
SSDeep 24576:gDhTSJJSHw3HoZk1/V69NPjxf28aufpH1kdSZvJ6Grld978XG:gxqUw3IZk1891V2wpH1kdSZvJdldyW
TLSH 0645F11576AADD03D4A62B7148F1D33447F5AD50E422C2076FE57EEFBA3AB822944383
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
cn.YT.resources
oli.Xlu.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RhythmTracker.Properties.Resources.resources
finn
[NBF]root.Data
mubw
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
QWnk.exe
Full Name
QWnk.exe
EntryPoint
System.Void fW.IB::xc()
Scope Name
QWnk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QWnk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
576
Main Method
System.Void fW.IB::xc()
Main IL Instruction Count
16
Main IL
br IL_001B: nop
call System.Void iff.kfg::Vut()
br IL_0028: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void iff.kfg::Vut()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_000F: nop
nop <null>
ret <null>
nop <null>
newobj System.Void cn.YT::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0026: nop
Module Name
QWnk.exe
Full Name
QWnk.exe
EntryPoint
System.Void fW.IB::xc()
Scope Name
QWnk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QWnk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
576
Main Method
System.Void fW.IB::xc()
Main IL Instruction Count
16
Main IL
br IL_001B: nop
call System.Void iff.kfg::Vut()
br IL_0028: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void iff.kfg::Vut()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_000F: nop
nop <null>
ret <null>
nop <null>
newobj System.Void cn.YT::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0026: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
cn.YT.resources
oli.Xlu.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RhythmTracker.Properties.Resources.resources
finn
[NBF]root.Data
mubw
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙