Suspicious
Suspect

PE Executable
MD5: ddebe7d9a357660b6feed761d96e2efd
Size: 859.14 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 ddebe7d9a357660b6feed761d96e2efd
Sha1 6db7abe74e94c227fa6fc93a69bcae898f1dcdbe
Sha256 8bc293957dc7682c4e0d265a34af321e71c533e41c93ee31e5d8cd5a23be9e7d
Sha384 5988f211ae93f584ba4d8509bf6536c9fabedc26081bfe51356a5857fb04c27a7d6f2fdba72bbd03fe0ed44aba89f50e
Sha512 219d15554113d8453ae1e854f07fb43895de8a7e3e381d10fede5265640e48c7565ea174039e69e9669dfb267419416a9809b68324b95cf4d689d0037957d9cc
SSDeep 24576:5jv7wpfyIvZD559IkIVOtSchi8Uuvm9ZCiL11C:pvUgI/0kFt1zZvsZCILC
TLSH 0A0512A4234ADD07D9950FB00970E7F50278BE99A504D3035FFDACEFBD39A612998286
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WinFormServer.Form1.resources
$this.Icon
[NBF]root.IconData
crt
[NBF]root.Data
WinFormServer.Properties.Resources.resources
YCQA
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
sNQw.exe
Full Name
sNQw.exe
EntryPoint
System.Void WinFormServer.Program::Main()
Scope Name
sNQw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sNQw
Assembly Version
1.5.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
70
Main Method
System.Void WinFormServer.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void WinFormServer.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
sNQw.exe
Full Name
sNQw.exe
EntryPoint
System.Void WinFormServer.Program::Main()
Scope Name
sNQw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sNQw
Assembly Version
1.5.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
70
Main Method
System.Void WinFormServer.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void WinFormServer.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WinFormServer.Form1.resources
$this.Icon
[NBF]root.IconData
crt
[NBF]root.Data
WinFormServer.Properties.Resources.resources
YCQA
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙