Suspicious
Suspect

WeTransfer Documents.exe

PE Executable
MD5: 9392967d0194cc91a9ea06df2ae2657e
Size: 755.71 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 9392967d0194cc91a9ea06df2ae2657e
Sha1 13a94dae2f6a743dcca4ad848b08d5cef9c1e8f6
Sha256 dbecf6e2bad4b37d6d724a33c84bd1826dbd4f6eb0c490ef152b261c67edc751
Sha384 ea9b5a65de613e91a5bc0a378cc08f69671d47ed6e87967c4ff29e6701cfc72b6526a73add25adc06420de0ce45b392e
Sha512 235bb918bcbeebd0e0714daa7ac5e92c03a67451b0fdf69d2a191473646744949d81fec5135e83fd6a211ccef8f345ce5a892fb3c8f9e7350044b42b3ace12f8
SSDeep 12288:CedYY8p8zD60Zc93ctYKXQ5Fg3GrkWcyCYjfK4xeksThWHncONwvhiqc87mkDBmm:CedYY86o3r1drFcyCYDK4xFsTYwjc8
TLSH 4EF4E15C7614F89FC883C8B18EA4DE75A6246D6AD30B811385E71CDFBA1DD86EE140E2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
TYHu
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
oQoT.exe
Full Name
oQoT.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
oQoT.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oQoT
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‌​‫‎‪‎‍‭‬​‌‫‫‌​‫‏‍‌‪‮‍‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‫‬‮‮‌​​​‪‌‍‍‭‎‭‭‫‪‌‪​‍‬‫‍‎‭‮‌‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::‭‎‍​‏‏‭‭‌‍​‎‍‮‍‌‫‪​‍‍‬‎‭‪‮(System.Windows.Forms.Form)
ret <null>
Module Name
oQoT.exe
Full Name
oQoT.exe
EntryPoint
System.Void WindowsFormsCSharpProject.Program::Main()
Scope Name
oQoT.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oQoT
Assembly Version
6.8.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
143
Main Method
System.Void WindowsFormsCSharpProject.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void WindowsFormsCSharpProject.Program::‌​‫‎‪‎‍‭‬​‌‫‫‌​‫‏‍‌‪‮‍‮()
ldc.i4.0 <null>
call System.Void WindowsFormsCSharpProject.Program::‫‬‮‮‌​​​‪‌‍‍‭‎‭‭‫‪‌‪​‍‬‫‍‎‭‮‌‮(System.Boolean)
newobj System.Void WindowsFormsCSharpProject.FormMain::.ctor()
call System.Void WindowsFormsCSharpProject.Program::‭‎‍​‏‏‭‭‌‍​‎‍‮‍‌‫‪​‍‍‬‎‭‪‮(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsCSharpProject.FormMain.resources
$this.Icon
[NBF]root.IconData
Perl
[NBF]root.Data
candlestickBindingSource.TrayLocation
openFileDialogTicker.TrayLocation
WindowsFormsCSharpProject.Form2.resources
WindowsFormsCSharpProject.Properties.Resources.resources
TYHu
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙