Suspicious
Suspect

PE Executable
MD5: de9c7aacaa23a029fcc8d819c7bb3643
Size: 713.73 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 de9c7aacaa23a029fcc8d819c7bb3643
Sha1 fda267aec308dca3e3c131ed41eedbb3c5a70647
Sha256 22d3d18fa3270b3fb4e70ad7109ac0aba259ca3c5d07542a3fdb9bafc1b88217
Sha384 045aa792587fd5c008a63000a541ff0631865b5265c705cae768c6aee82957f08a0c7e4506019f658327d12b2acf6df5
Sha512 c6800b047226e1923fb374fcb7933e443d186dcbbe892ea11e59e3ac5cd5fea1aed68dfd5b88b66d0f6b67320a12ece9a79b5251146260e36c13df996f3a0ce9
SSDeep 12288:oGHW3MtFY14DXO8rBsLIAiTQsyu7GD8PG7RbgwKMbx07+gf9/4aNdaW0JCcHLUXG:oGHqMvWV8tqIAhDRy7X3Ndn0XEO4w
TLSH 61E42206B1ADDE47E4531FF80871D17157B83E9AC972EA474FCA7CCBB82AB84091464B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AlertDisplay.Forms.MainForm.resources
AlertDisplay.Properties.Resources.resources
Jece
[NBF]root.Data
[NBF]root.Data-preview.png
Mars
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: tQIw.pdb
Module Name
tQIw.exe
Full Name
tQIw.exe
EntryPoint
System.Void AlertDisplay.Program::Main()
Scope Name
tQIw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tQIw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
117
Main Method
System.Void AlertDisplay.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AlertDisplay.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
tQIw.exe
Full Name
tQIw.exe
EntryPoint
System.Void AlertDisplay.Program::Main()
Scope Name
tQIw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tQIw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
117
Main Method
System.Void AlertDisplay.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AlertDisplay.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AlertDisplay.Forms.MainForm.resources
AlertDisplay.Properties.Resources.resources
Jece
[NBF]root.Data
[NBF]root.Data-preview.png
Mars
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙