Suspicious
Suspect

6f4a8ec49d5264550b9b0721fe1c8beb

PE Executable
MD5: 6f4a8ec49d5264550b9b0721fe1c8beb
Size: 568.32 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 6f4a8ec49d5264550b9b0721fe1c8beb
Sha1 d0f347e623aafc8fe883d02b26c204779707901a
Sha256 ed5c7487744fe7d6ae02300d4bbd1a2b2b7dda10efeff9b27406020a5f1931a3
Sha384 b299e0061826c13b16b987705e60234ae7608a4496f0f0ab9fc81c692ea4a2ca9715f9d2480cdc926cff5d92d9e6eeeb
Sha512 a8fbfd152d6ef2c694f2bf2a19f1c7d3ef9069b3253f37dbd0c3257eb8bec2c2fc4b34771aa6841d9bfbc13e684297628dd5f50c07967b00e4b76e362e4777e6
SSDeep 12288:VHDAsLJMwuiMnoDI62Uhc9LHE7T25Fnuhan2GX5p1+bL59B7/:VcsLJMwvDIQhijEObn1
TLSH F7C4D09D3240F19FC497DA328964DEB4DA606D6A9307D30395EB2EEFB90D586CF140E2
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
iiPu
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
qNPJ.exe
Full Name
qNPJ.exe
EntryPoint
System.Void StudyGuide.Program::Main()
Scope Name
qNPJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qNPJ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void StudyGuide.Program::Main()
Main IL Instruction Count
43
Main IL
nop <null>
ldc.i4 -56146752
ldc.i4 -1653499651
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.6 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0083: ret
ldc.i4.0 <null>
call System.Void StudyGuide.Program::‍‮‪‭‪‫‫‬‮‏‏‏‮‮‌‫‪‍‏‌‬‮‫‮‭‮(System.Boolean)
ldloc.0 <null>
ldc.i4 390417611
mul <null>
ldc.i4 -1153268198
xor <null>
br.s IL_0006: ldc.i4 -1653499651
nop <null>
ldloc.0 <null>
ldc.i4 540297930
mul <null>
ldc.i4 -2036494428
xor <null>
br.s IL_0006: ldc.i4 -1653499651
nop <null>
newobj System.Void StudyGuide.MainForm::.ctor()
call System.Void StudyGuide.Program::‎‍‍‬‬‫‭‪‫‬‮‍‍‬‫‪‏‏‏‮‌‮‪‮(System.Windows.Forms.Form)
nop <null>
ldloc.0 <null>
ldc.i4 1352673612
mul <null>
ldc.i4 -243238625
xor <null>
br.s IL_0006: ldc.i4 -1653499651
call System.Void StudyGuide.Program::‏‌‮‌‭‌‪‬‎‬‎‎‎‪‎‪‮‍‎‌​‎‫‎‭‫‬‎‬‍‮()
ldloc.0 <null>
ldc.i4 7661622
mul <null>
ldc.i4 -1720887859
xor <null>
br.s IL_0006: ldc.i4 -1653499651
ret <null>
Module Name
qNPJ.exe
Full Name
qNPJ.exe
EntryPoint
System.Void StudyGuide.Program::Main()
Scope Name
qNPJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qNPJ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void StudyGuide.Program::Main()
Main IL Instruction Count
43
Main IL
nop <null>
ldc.i4 -56146752
ldc.i4 -1653499651
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.6 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0083: ret
ldc.i4.0 <null>
call System.Void StudyGuide.Program::‍‮‪‭‪‫‫‬‮‏‏‏‮‮‌‫‪‍‏‌‬‮‫‮‭‮(System.Boolean)
ldloc.0 <null>
ldc.i4 390417611
mul <null>
ldc.i4 -1153268198
xor <null>
br.s IL_0006: ldc.i4 -1653499651
nop <null>
ldloc.0 <null>
ldc.i4 540297930
mul <null>
ldc.i4 -2036494428
xor <null>
br.s IL_0006: ldc.i4 -1653499651
nop <null>
newobj System.Void StudyGuide.MainForm::.ctor()
call System.Void StudyGuide.Program::‎‍‍‬‬‫‭‪‫‬‮‍‍‬‫‪‏‏‏‮‌‮‪‮(System.Windows.Forms.Form)
nop <null>
ldloc.0 <null>
ldc.i4 1352673612
mul <null>
ldc.i4 -243238625
xor <null>
br.s IL_0006: ldc.i4 -1653499651
call System.Void StudyGuide.Program::‏‌‮‌‭‌‪‬‎‬‎‎‎‪‎‪‮‍‎‌​‎‫‎‭‫‬‎‬‍‮()
ldloc.0 <null>
ldc.i4 7661622
mul <null>
ldc.i4 -1720887859
xor <null>
br.s IL_0006: ldc.i4 -1653499651
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
iiPu
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙