Suspicious
Suspect

b8f6bc88632c3b006dbe33e190556fb9

Share on LinkedIn
Print
PE Executable
MD5: b8f6bc88632c3b006dbe33e190556fb9
Size: 879.62 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b8f6bc88632c3b006dbe33e190556fb9
Sha1 ec061a1eda56695d9da02b2d22bef84e640e0835
Sha256 e52c8a7aea791e6935c21da222a01172f05216e551bdd46bacfc87a7338934a0
Sha384 270150757c2f59ace1e1894a71774580d799fd1fe79cdf7535b3300b7ea35b732035651eb91a20dd48d6ba9bd0951eba
Sha512 0f1972b833996f847740f0c4af978254de7c5a3197a6e3afb373539cd5897a5d0f123f3c3a199e56970cc4b377c87d2c1bb105e15fa12402c87b9a26b1aeea8e
SSDeep 12288:Wxzl4S2Pd8A13+WwsIpKV2RJDt6oyW/EakSjf6XdPqIc+cgaau/AlvIbMjEzs:kzKBd5lI8Et6oydakqfpALpCoSs
TLSH 7115E01077B98F02CCAAA7F04530E1B207F57EADAA10E30E8DE17DEB7679B505A44653
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Library.FormMenu.resources
$this.Icon
[NBF]root.IconData
TCA
[NBF]root.Data
Library.FormBook.resources
BookFlowLibrary.Properties.Resources.resources
TtiIz
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
ALRQW.exe
Full Name
ALRQW.exe
EntryPoint
System.Void Library.Program::Main()
Scope Name
ALRQW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ALRQW
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
759
Main Method
System.Void Library.Program::Main()
Main IL Instruction Count
5
Main IL
nop <null>
newobj System.Void Library.FormMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ALRQW.exe
Full Name
ALRQW.exe
EntryPoint
System.Void Library.Program::Main()
Scope Name
ALRQW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ALRQW
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
759
Main Method
System.Void Library.Program::Main()
Main IL Instruction Count
5
Main IL
nop <null>
newobj System.Void Library.FormMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
?huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙