Suspicious
Suspect

cdf69e3345e9e518a03633c28358268b

PE Executable
MD5: cdf69e3345e9e518a03633c28358268b
Size: 1.48 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 cdf69e3345e9e518a03633c28358268b
Sha1 687ce6f9816eb8ad80f532ba2c832cf5476bdca0
Sha256 41aa2a9f47277b32efbb369b5b92c79d444d3c524cd55142d9e85603ddea3478
Sha384 f72c675e98e0caffef9f92d9204c79b2e43a668d022f2f237d1552f752fb0ec4acf9ef60e49c0ade54a3e4abb688e40e
Sha512 764e0e570d86f04b7151440139f8648a8a4f630f4985fe86521461844759f4420ece4521ab688496604a8c261c3e20325c224755f8a2c0c89c18da34bc013500
SSDeep 24576:h4d+K3jGBJ8sRJWmMFbXZUUlwvuQOKs/NvRDmZ6fcmAOEiDwrggF8bwQR+io:h4d+6jG8sRJWNZTlFx/9RDOmjcMuQRa
TLSH 74651258336BDC06C5295F741C31E3F81FB85D98A561E2039EEABFEBB935A0068152C7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FishFarm.Properties.Resources.resources
BYpD
[NBF]root.Data
[NBF]root.Data-preview.png
Sed
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
OqHQ.exe
Full Name
OqHQ.exe
EntryPoint
System.Void FishFarm.Program::Main()
Scope Name
OqHQ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OqHQ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
247
Main Method
System.Void FishFarm.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FishFarm.FormMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
OqHQ.exe
Full Name
OqHQ.exe
EntryPoint
System.Void FishFarm.Program::Main()
Scope Name
OqHQ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OqHQ
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
247
Main Method
System.Void FishFarm.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void FishFarm.FormMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
FishFarm.Properties.Resources.resources
BYpD
[NBF]root.Data
[NBF]root.Data-preview.png
Sed
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙