Suspicious
Suspect

PE Executable
MD5: e5925d8671c7a89952bc932399af51a7
Size: 667.65 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 e5925d8671c7a89952bc932399af51a7
Sha1 b2638c04c6648bead12f9611435b8d312e3c03a2
Sha256 10f246e9a23f84a9e80787e654d3f5612eaded3b992ccaa7a92a94ce8676e40f
Sha384 17f89cdab47d69b774b3da7787b74d6249cea1f4c82382137a267e061fcd65b9d5858a87bfc7765e7c8b8a3c8327e3d0
Sha512 388a09f6fbcf6ea709dd6c9266200eb04a6aec8d1c697b8443673f3da122015a19e3ddbc789be69d390de0c7d76b177a5283774b46a42fe5a233f8724fd6a9b8
SSDeep 12288:0amRsA9hu95y89jzJCk+DgMCiZ2Yt4ZO7oNDhZmgftKAu3Mya+nI:ERsA9hu95y89jkd1CiMYh70DhZXgMy
TLSH B1E40296131BD913D4D207F88960E3B4A3799EADA511D3679EFD7CDF7C38700A8902A2
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PassGenerator.Forms.MainForm.resources
PassGenerator.Properties.Resources.resources
Ce
[NBF]root.Data
gold_bars
[NBF]root.Data
[NBF]root.Data-preview.png
uzUJ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: Hqvb.pdb
Module Name
Hqvb.exe
Full Name
Hqvb.exe
EntryPoint
System.Void PassGenerator.Program::Main()
Scope Name
Hqvb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Hqvb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
99
Main Method
System.Void PassGenerator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void PassGenerator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PassGenerator.Forms.MainForm.resources
PassGenerator.Properties.Resources.resources
Ce
[NBF]root.Data
gold_bars
[NBF]root.Data
[NBF]root.Data-preview.png
uzUJ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙