Suspicious
Suspect

9870cdf26ed8ce382463b7f11a23b28a

PE Executable
MD5: 9870cdf26ed8ce382463b7f11a23b28a
Size: 952.32 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 9870cdf26ed8ce382463b7f11a23b28a
Sha1 43b5e31530b1bb58fdd801de9a67ad3640ac1b92
Sha256 ec4e5a7900d98e13f95ddcc520878c0776da2015238686e37758d0c9b23f9d11
Sha384 33a883f7f640f094974cee39aeaff1f2fcbea42ef833448aa00544597b0518c2328d3d025b1f809a7aba4676715d297a
Sha512 7c9949c02ba67fd7751f8353d82ee6daf49aa60d5efd972d8f364d6cab060d20df4131088fb86838ac134b8c423eb25fac4d4f57be75b9038bd77f1e2552a70a
SSDeep 12288:jGE4FoxoBQhBGY5c25kID5JZjE+rm9OSc0l4oxwNIx5NQJd5ISVZ6WABWWv+W:4/BQT5d5kIDZI+rBS/mv1b6lW
TLSH 1215F0186FF69AD7D4A617B80271E63016B79F4AA531D2068EEDBCF73A327031913352
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QuanLyThuVienCaNhan.GUI.frmLogin.resources
$this.Icon
[NBF]root.IconData
Qi
[NBF]root.Data
QuanLyThuVienCaNhan.GUI.frmMain.resources
QuanLyThuVienCaNhan.GUI.frmThemSuaSach.resources
QuanLyThuVienCaNhan.Properties.Resources.resources
ProjectedW
[NBF]root.Data
[NBF]root.Data-preview.png
rjOU
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
OAQJ.exe
Full Name
OAQJ.exe
EntryPoint
System.Void QuanLyThuVienCaNhan.Program::Main()
Scope Name
OAQJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OAQJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\tFkNxbRQyq\src\obj\Debug\OAQJ.pdb
Total Strings
428
Main Method
System.Void QuanLyThuVienCaNhan.Program::Main()
Main IL Instruction Count
21
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void QuanLyThuVienCaNhan.GUI.frmLogin::.ctor()
stloc.0 <null>
ldloc.0 <null>
callvirt System.Windows.Forms.DialogResult System.Windows.Forms.Form::ShowDialog()
ldc.i4.1 <null>
ceq <null>
stloc.1 <null>
ldloc.1 <null>
brfalse.s IL_002E: ret
nop <null>
newobj System.Void QuanLyThuVienCaNhan.GUI.frmMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QuanLyThuVienCaNhan.GUI.frmLogin.resources
$this.Icon
[NBF]root.IconData
Qi
[NBF]root.Data
QuanLyThuVienCaNhan.GUI.frmMain.resources
QuanLyThuVienCaNhan.GUI.frmThemSuaSach.resources
QuanLyThuVienCaNhan.Properties.Resources.resources
ProjectedW
[NBF]root.Data
[NBF]root.Data-preview.png
rjOU
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙