Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 80e52a15a6f1356a18b961cec5a19ab3
Size: 856.58 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 80e52a15a6f1356a18b961cec5a19ab3
Sha1 32b804e150b252ad64c794bce3a4608fa2bacb76
Sha256 54f0ad3a45963863d0fac39e1b6028ed64d2a05910dfa68e6a7f2a2dfed0bb72
Sha384 b1bf666a70e892d7480e98f076bfd3b725e513c9135b57677d132b31704af4cf008e57841e2b56547d60951a743ad636
Sha512 2b8fa6a32a3858fcf317c682f695cef60d3ac9a9ff731ffd54effca1758ecbb9e371d4bcec3e8e58b9a9d74110222c3faaa0129e4e49ce978a89647f2ccce991
SSDeep 24576:cosafKY9V0sVMlStq0MixTLDd2e2ZTCXSpSjiyBUmc5xoB:53SsVQtrgT927dgu9n4B
TLSH D305CE3032AD9963C6B552F40460D17533A76ECF281AE2DA4DDABCCB7CE4BC11B95A43
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
QLDTDD_FPT.AM_Edit.resources
QLDTDD_FPT.Properties.Resources.resources
arkR
[NBF]root.Data
[NBF]root.Data-preview.png
QLDTDD_FPT.StaffManagementForm.resources
$this.Icon
[NBF]root.IconData
kc
[NBF]root.Data
Name Value
Module Name
feFa.exe
Full Name
feFa.exe
EntryPoint
System.Void QLDTDD_FPT.Program::Main()
Scope Name
feFa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
feFa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
975
Main Method
System.Void QLDTDD_FPT.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void QLDTDD_FPT.Mainform::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
feFa.exe
Full Name
feFa.exe
EntryPoint
System.Void QLDTDD_FPT.Program::Main()
Scope Name
feFa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
feFa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
975
Main Method
System.Void QLDTDD_FPT.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void QLDTDD_FPT.Mainform::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
PDB Path PATH
fehuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙