Suspicious
Suspect

a151ba6aa28f0908f16f8f17057c5a64

PE Executable
MD5: a151ba6aa28f0908f16f8f17057c5a64
Size: 706.05 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 a151ba6aa28f0908f16f8f17057c5a64
Sha1 efa55b7ab16a87e6c7935f16d64d43af04d81d78
Sha256 d11155aa93eeac5cfb4fec126d89c65c0b46eda37765954d2eb68f10a8aa4792
Sha384 971eccdd84e7490f5056097bd9d38cacb0c2eae13f1b2aebf98cb83d080d3dc95ab96663167b409c9bf7878512c326e5
Sha512 98b965b7281f6f4b0ec220566394d408193c02ac7d373c4a17f3fe2f11d54d7a79b069ed2fea127cef855c1ba065a31f5809b2e6a2d6e5726b1ffdc246bd25f2
SSDeep 12288:J1kya3jo771ePt+yyAIBUszmR2XEZ15QebbyY1YezG11GRFnPp:J1kN3jsK65asqIUNQsOY+ee1u
TLSH 40E40188274BEA07CDA547B80A71E67413A91EEFED02E74A4FD47DEB7971F010A51283
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AgatePrintingStation.ClientSolution.AddClientForm.resources
AgatePrintingStation.frmMain.resources
$this.Icon
[NBF]root.IconData
MN
[NBF]root.Data
AgatePrintingStation.Properties.Resources.resources
FVpO
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
qLEV.exe
Full Name
qLEV.exe
EntryPoint
System.Void AgatePrintingStation.Program::Main()
Scope Name
qLEV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qLEV
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
157
Main Method
System.Void AgatePrintingStation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AgatePrintingStation.frmMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
qLEV.exe
Full Name
qLEV.exe
EntryPoint
System.Void AgatePrintingStation.Program::Main()
Scope Name
qLEV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qLEV
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
157
Main Method
System.Void AgatePrintingStation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AgatePrintingStation.frmMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AgatePrintingStation.ClientSolution.AddClientForm.resources
AgatePrintingStation.frmMain.resources
$this.Icon
[NBF]root.IconData
MN
[NBF]root.Data
AgatePrintingStation.Properties.Resources.resources
FVpO
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙