Suspicious
Suspect

PE Executable
MD5: be476a142a1187c0466a9c434e7f0f50
Size: 921.6 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 be476a142a1187c0466a9c434e7f0f50
Sha1 7ce7a1a95826b0d247ac9c75a969d70a18efa368
Sha256 b020144dfab196ac6ddaa6442884f16734746cf346b859cee50660fbb938271f
Sha384 ab18a0848e3b17de54dd7222ed7ea7539a9b0405240d5e210f4ba194d2081755110f914a6d502c60dcd79af8cf5562de
Sha512 5b3eae9004bf27ff1109412c294f773695ddbe50f7a04948682a617db739c1cebda7aabb68e4bb67ddc02c3e7ad2cd15159fe91f649006b09befc1461bac99ef
SSDeep 12288:sKx0OWJV0bsf+N+KON0Bvk4hqiXS/lZ7Eyr5sQZyf+Z0hDk3UxOlh8xUjD:svOb/NTK0BvRPXST7/Zyf+ShIoOwxq
TLSH D61512A52287D923C4AA07B04DA1E3F4A37A9EC8F512C3071ED8BDDB7D1AB052D90757
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorConvert.MainForm.resources
ColorConvert.Properties.Resources.resources
KS
[NBF]root.Data
QHsS
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: uhQQ.pdb
Module Name
uhQQ.exe
Full Name
uhQQ.exe
EntryPoint
System.Void ColorConvert.Program::Main()
Scope Name
uhQQ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
uhQQ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
140
Main Method
System.Void ColorConvert.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ColorConvert.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ColorConvert.MainForm.resources
ColorConvert.Properties.Resources.resources
KS
[NBF]root.Data
QHsS
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙