Suspicious
Suspect

PE Executable
MD5: c33645ccd7b90254f233e7fa3f9eb0c5
Size: 720.39 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 c33645ccd7b90254f233e7fa3f9eb0c5
Sha1 34aeff118857876ad92545b1c2ae8773f2145818
Sha256 40c432e0dbcfac20f6fd780e6e90c63e062db0ccc17eb007db0e73ee97dc7c88
Sha384 bd6bf585e8c53cc70fd333b5b61859b136c6c2d428c8830e5fc2a616da345d28d69c78e33b851ec7b13fc39cbfb2cb7b
Sha512 6aa23ce033e190fb0af7efca768721dd99dc70ac1c497515ac06d6c4c88fc8401fd24a127f17ea824f43ff293718016c4f4473803e49e2483fb5c5c563da394f
SSDeep 12288:RV3L/rb8WkuNuxYkv9B0SHOyEqTpqC0mSdqNEbFQfrPynO/MNvWMkR:z7v+mkvYSu0Tb+RMrPziW7
TLSH 20E412281B8EDE13C4C11B7066A0D77922B4ED59EA11C2134FFEACEBB879A053D1D355
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
oiMundo.Form1.resources
$this.Icon
[NBF]root.IconData
NI
[NBF]root.Data
oiMundo.Properties.Resources.resources
BtAh
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xAC800 size 13832 bytes
Info
PDB Path: ?
Module Name
eQtT.exe
Full Name
eQtT.exe
EntryPoint
System.Void oiMundo.Program::Main()
Scope Name
eQtT.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
eQtT
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
161
Main Method
System.Void oiMundo.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void oiMundo.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
oiMundo.Form1.resources
$this.Icon
[NBF]root.IconData
NI
[NBF]root.Data
oiMundo.Properties.Resources.resources
BtAh
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙