Suspicious
Suspect

PE Executable
MD5: 85f729eb83f21ddc7de30cbf07419906
Size: 405.5 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 85f729eb83f21ddc7de30cbf07419906
Sha1 aef4409b3ed90086e5e9362a8bad529e31deb97d
Sha256 43cee7b614906341cc511f6a014271a983dc24f3c85aae50d3c26bbe39e8e0c0
Sha384 8ae3175f6465a573d28bb86b8ba2a6cac2a2b4f4c73ed20162afc71242caf3da490ac634c37035582cde92f185891f69
Sha512 6ef0b4d3f71d7c10e77f922d5d4832bc427a9ad7e00090fcfff13c06a99ec12f360af32ff0d9ef9c83e81727091732cabf0b49cedd3e3a06d6a8a3699ea133e5
SSDeep 12288:HM+Vrye9HRNvrufyuJdVH+AubwOKhngyYupry:s+VTHR5ruq6PHtubwOKhgyN
TLSH B68423426217AFE1C9D2D6349876EBA48BDCA205057DCFBDB65E0F2F4D0B34BC6904A1
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Mkqtnrbdtv.Properties.Resources.resources
Crhqyy
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Mkqtnrbdtv.exe
Full Name
Mkqtnrbdtv.exe
EntryPoint
System.Void Mkqtnrbdtv.Tzdgphpsbsu::Main()
Scope Name
Mkqtnrbdtv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Mkqtnrbdtv
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
6
Main Method
System.Void Mkqtnrbdtv.Tzdgphpsbsu::Main()
Main IL Instruction Count
7
Main IL
br IL_000C: call System.Boolean BuY2LQCcHVv8WXT1T6.d7Iye37klmFdp6Dl7C::kpBJDlw1B()
newobj System.Void System.Exception::.ctor()
throw <null>
ret <null>
call System.Boolean BuY2LQCcHVv8WXT1T6.d7Iye37klmFdp6Dl7C::kpBJDlw1B()
brtrue IL_000B: ret
br IL_0005: newobj System.Void System.Exception::.ctor()
Module Name
Mkqtnrbdtv.exe
Full Name
Mkqtnrbdtv.exe
EntryPoint
System.Void Mkqtnrbdtv.Tzdgphpsbsu::Main()
Scope Name
Mkqtnrbdtv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Mkqtnrbdtv
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
6
Main Method
System.Void Mkqtnrbdtv.Tzdgphpsbsu::Main()
Main IL Instruction Count
7
Main IL
br IL_000C: call System.Boolean BuY2LQCcHVv8WXT1T6.d7Iye37klmFdp6Dl7C::kpBJDlw1B()
newobj System.Void System.Exception::.ctor()
throw <null>
ret <null>
call System.Boolean BuY2LQCcHVv8WXT1T6.d7Iye37klmFdp6Dl7C::kpBJDlw1B()
brtrue IL_000B: ret
br IL_0005: newobj System.Void System.Exception::.ctor()
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Mkqtnrbdtv.Properties.Resources.resources
Crhqyy
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙