Suspicious
Suspect

PE Executable
MD5: 8a418fdfc247aa7d7fe85a4b9385870f
Size: 706.56 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 8a418fdfc247aa7d7fe85a4b9385870f
Sha1 00db06008b884465e32307d26e554d982952ef88
Sha256 a7084e26390ab1dbd0318403c7f73dc63d3ca65ba7fb289349e88de4e46dc98f
Sha384 9580e025cf8bc46f1f6f72e06519ab0194d7e5c278c5e2f0e0d00a7deb17ece1d1952f833fb639631cd4f3c0c111c75b
Sha512 eb03c367581849890b5c0997ebaa8e0b814a99ac59c1475151f748b38da08368d4a0fc5ca976b100b0eec93936af258002da7c62ad8b077517076e32eef570f7
SSDeep 12288:a8Bc6R0qec7fCNr0UpYBcHar9MtXgJtBuU9UXkfZvfXVfBS9LtGjxv:ax6mqx7fEr0xBcstJCqpd5SxtG
TLSH 45E40144236EDE12D0A56FFA9C30C17027797ECAA462C24A9FC57EDF78B5B204985353
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AutoWallpaperChanger.Form1.resources
AutoWallpaperChanger.Properties.Resources.resources
LayerT
[NBF]root.Data
YWudF
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: qQNKI.pdb
Module Name
qQNKI.exe
Full Name
qQNKI.exe
EntryPoint
System.Void AutoWallpaperChanger.Program::Main()
Scope Name
qQNKI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qQNKI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
211
Main Method
System.Void AutoWallpaperChanger.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AutoWallpaperChanger.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
qQNKI.exe
Full Name
qQNKI.exe
EntryPoint
System.Void AutoWallpaperChanger.Program::Main()
Scope Name
qQNKI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qQNKI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
211
Main Method
System.Void AutoWallpaperChanger.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AutoWallpaperChanger.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AutoWallpaperChanger.Form1.resources
AutoWallpaperChanger.Properties.Resources.resources
LayerT
[NBF]root.Data
YWudF
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙