Suspicious
Suspect

PE Executable
MD5: bc1b501655e83811e6a2294e3d8b930e
Size: 631.81 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 bc1b501655e83811e6a2294e3d8b930e
Sha1 11fce86af2bc3ed47981a8cf971955ce0c4ba773
Sha256 27a476a5839cb8b1c8dd5dcbe089978cb3fd10a4c4424fdfd79313802802be47
Sha384 92ae1e65cda1981d91e8340733a82b9732b4554051a830c823fcb6973ee7e9b8ae6a09100cb2b9c229c4235cd0dd015d
Sha512 7da923e520c3c7f5707a0a1b53f97af6910677a0dd7a0737d81c941fefb32c2b8d745a3da4a27cdbc694c01767ae29542c308d546ffb8b32efd4f5a0cc858ce7
SSDeep 12288:KGZMrXYKtoTlgAajRabGN1U5gCyvXPO6Tqq:tgYGKlgAB1xApq
TLSH 93D4E097339EE71ED0912BB46571E3380779AE47A416E3067AEAFCEF342874419413E2
PeID
.NET executableMEW 11 SE 1.2Microsoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QueryFormat.Forms.MainForm.resources
QueryFormat.Properties.Resources.resources
WR
[NBF]root.Data
vzGS
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: rsuv.pdb
Module Name
rsuv.exe
Full Name
rsuv.exe
EntryPoint
System.Void QueryFormat.Program::Main()
Scope Name
rsuv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rsuv
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
638
Main Method
System.Void QueryFormat.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void QueryFormat.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
rsuv.exe
Full Name
rsuv.exe
EntryPoint
System.Void QueryFormat.Program::Main()
Scope Name
rsuv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rsuv
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
638
Main Method
System.Void QueryFormat.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void QueryFormat.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QueryFormat.Forms.MainForm.resources
QueryFormat.Properties.Resources.resources
WR
[NBF]root.Data
vzGS
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙