Suspicious
Suspect

PE Executable
MD5: c42aa545ecc27649ebb2b2c769132b8e
Size: 768.51 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 c42aa545ecc27649ebb2b2c769132b8e
Sha1 42271f608c34f14c58ad88ff506bdca71eb2d638
Sha256 024e0ec6668fa78bb43f5d05ae30588e82c4429fdbf36034cbdd9895aee4e458
Sha384 9424cd65c535c20c2b5d619f062a6e803fe6900526c5b36305065f1873ac36490bb40629559877d1f3ed6e74298c449e
Sha512 7be7ae8c5e7a705b3c94639afa818fe8cb0df97be6f9dcafb37b1cde2d64029f889a47be43b6118d7a77893a0c54704ea4b4de12738c5e8f66418e38a8e0bf1e
SSDeep 12288:pNnbjgIVXuzEyYCDTi0igcYQAQIkhyn5M7fvzw1TqItGCt995AnZ6lRfMRiR:pNnbxNuoyYCDGNzYQCgyoIW/Ct9922f7
TLSH 43F4021E69D78492C1A53FB847E3C2B54A382FE64473CAD7BFE67CCF39259006602265
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
FrontEnd.MainForm.resources
$this.Icon
DQ
BackEndLibrary.Properties.Resources.resources
LKwE
Name Value
Module Name
ZLqS.exe
Full Name
ZLqS.exe
EntryPoint
System.Void FrontEnd.Program::Main()
Scope Name
ZLqS.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ZLqS
Assembly Version
25.174.802.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
228
Main Method
System.Void FrontEnd.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void FrontEnd.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
ZLqS.exe
Full Name
ZLqS.exe
EntryPoint
System.Void FrontEnd.Program::Main()
Scope Name
ZLqS.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ZLqS
Assembly Version
25.174.802.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
228
Main Method
System.Void FrontEnd.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void FrontEnd.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
FrontEnd.MainForm.resources
$this.Icon
DQ
BackEndLibrary.Properties.Resources.resources
LKwE
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
c42aa545ecc27649ebb2b2c769132b8e
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
c42aa545ecc27649ebb2b2c769132b8e
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙