Suspicious
Suspect

PE Executable
MD5: 909de0b8a1c7057d61b10130c221522e
Size: 733.18 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 909de0b8a1c7057d61b10130c221522e
Sha1 f21e4bcb1f9006d91fe653300b805c9e3fd228d2
Sha256 a42530d23d10ce4fb58b72111a6d09c6122dca4ff9fe56550d8e5acbacaab5f2
Sha384 6f3318c5b097391954136ce920afb60d2d9fcea1bf951df866e9ec68273a57330af1f0fbda7e88d7cc87aba9158d8f5a
Sha512 c352df5e3bcbec09b7b8008ee7a69409d0074f2a83d72ce996097632d538812f09d7245150bd58e7dda0ad6d5a52f6558b3327ecea78b1012b3a75477b75aa09
SSDeep 12288:BO3L/rb8WkKwK1c2vwLXRYaEfdiEDyLOwwv4pO4i/ZgL2JsYN/xrX45NpToxEb0a:u7v+Kv/4XRFAdiZV44pOPZtJsMgeE7
TLSH F8F402682F4DEE02D88527745A21F3752220AD9DDD11D2134FEEBDEFB879B12395C282
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
oiMundo.Form1.resources
$this.Icon
[NBF]root.IconData
NI
[NBF]root.Data
oiMundo.Properties.Resources.resources
EoTr
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
nQhZ.exe
Full Name
nQhZ.exe
EntryPoint
System.Void oiMundo.Program::Main()
Scope Name
nQhZ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nQhZ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
161
Main Method
System.Void oiMundo.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void oiMundo.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
oiMundo.Form1.resources
$this.Icon
[NBF]root.IconData
NI
[NBF]root.Data
oiMundo.Properties.Resources.resources
EoTr
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙