Suspicious
Suspect

d5a1c25a0d94a939935412058154c8ef

PE Executable
MD5: d5a1c25a0d94a939935412058154c8ef
Size: 820.74 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 d5a1c25a0d94a939935412058154c8ef
Sha1 f3d48d753ee43f069763fcf06a8c9e3536dfed8b
Sha256 46038f8f6f10cbee2ea6654ab97a7664365087b7b86bb3ee783ae0428a411eb4
Sha384 e2fe31cce0b6a21ae0a1d7b6aab926fd67c27f273c0d91debf7815eeaaf6b0270fd1cdd4d298434fd11114df7a70d788
Sha512 b25b016938071d8407124fe85c5404bba6176f02609e34ce488749c1d741f46462b8fa9df711b858f58f7523e593b21db4d15d51c3e787ea17d6d9501b9a5d53
SSDeep 24576:d81lEufOA4dd1SPdaAZOHRQEvX4JhDeZ:qfEufgkPEAZ+RQEAJhDe
TLSH 9C051258B3A1DB12E8730BF51532E93103B07CAA7A21E25A4EE9BDDB7B337146414727
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RainPainter.Properties.Resources.resources
NADw
[NBF]root.Data
[NBF]root.Data-preview.png
Pun
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
BEqT.exe
Full Name
BEqT.exe
EntryPoint
System.Void RainPainter.Program::Main()
Scope Name
BEqT.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BEqT
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
249
Main Method
System.Void RainPainter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RainPainter.CanvasForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
BEqT.exe
Full Name
BEqT.exe
EntryPoint
System.Void RainPainter.Program::Main()
Scope Name
BEqT.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
BEqT
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
249
Main Method
System.Void RainPainter.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RainPainter.CanvasForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RainPainter.Properties.Resources.resources
NADw
[NBF]root.Data
[NBF]root.Data-preview.png
Pun
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙