Suspicious
Suspect

7fd532f4b4962d4f9cf21d09ea488399

PE Executable
MD5: 7fd532f4b4962d4f9cf21d09ea488399
Size: 737.79 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 7fd532f4b4962d4f9cf21d09ea488399
Sha1 ef22bb22c8d9f30a1ab463ab29324f1f84b8d40d
Sha256 e8d627c2a8329b72677baf63e3eaf979c53d8a642331237a6e52d01377fc9543
Sha384 c3eee7ceb9acd7bfef5498bbf1bfce82bb9e115dbebc6b0e813226e88d12fb3b560bf009d22fa43b6ef70ddfbac77706
Sha512 df8129e80e04c1597122dc0ad1294cb6251bd922948a5d7291e5c6ff91174b862b9741e852f62b549c69bc646bd0a3718d08be86f5f8ecd233ab8e3889dde4ed
SSDeep 12288:mm0UL0Rk1FaKxBZ2+rk1fWBk891V5sKzKbSWVxFmPxRht9zmeBQx339:gwHhEfWBkuubVxFmPxRxzmWC3N
TLSH BCF4019463EA8606E5BE1B741A72E63007BC7DAA9931C61D0FC92DDFBC71B808D60353
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MonitorSync.Properties.Resources.resources
HQ
[NBF]root.Data
vCDE
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
HqLw.exe
Full Name
HqLw.exe
EntryPoint
System.Void MonitorSync.Program::Main()
Scope Name
HqLw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
HqLw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
491
Main Method
System.Void MonitorSync.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MonitorSync.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
Hqhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MonitorSync.Properties.Resources.resources
HQ
[NBF]root.Data
vCDE
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
Hqhuhuhuhu
7fd532f4b4962d4f9cf21d09ea488399
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙