Suspicious
Suspect

PE Executable
MD5: e8bd1d4b441205ec2116e1acea654eca
Size: 540.16 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 e8bd1d4b441205ec2116e1acea654eca
Sha1 3f45a4787f77e43f9c609fbe0a34600242361dac
Sha256 2cd68c73f407a88d29c7599a427f747f4f686dd12c33be96589d49f2f879d080
Sha384 6dd2fdbcbaa9f5a3d7283e512b7761c98df8e848384ed4728725fa677d57149cef51ca3f7f143f1173da42761c689515
Sha512 696fee45cef31cb58549891fbf827470f7fd53e7da487612d69c89e64fe484faa2b4595ca790567578864b9183768e4c1e412489d3601610721e31925507c552
SSDeep 12288:xBBf7+ny1Ouo0k1C++9RBiejeMtiaFgTn:xvf75DoNDqb9uL
TLSH 35B4F1686B5EED12C9D15BB008A0E3B26334CE4DD520D6038FEAADDBB469F56385D2C1
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
testeMatematico.Form1.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
CHT
[NBF]root.Data
timer1.TrayLocation
testeMatematico.Properties.Resources.resources
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
shHb
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
lqud.exe
Full Name
lqud.exe
EntryPoint
System.Void testeMatematico.Program::Main()
Scope Name
lqud.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lqud
Assembly Version
2.2.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
104
Main Method
System.Void testeMatematico.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void testeMatematico.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
testeMatematico.Form1.resources
$this.BackgroundImage
[NBF]root.Data
[NBF]root.Data-preview.png
$this.Icon
[NBF]root.IconData
CHT
[NBF]root.Data
timer1.TrayLocation
testeMatematico.Properties.Resources.resources
fabrica24
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica25
[NBF]root.Data
[NBF]root.Data-preview.png
fabrica26
[NBF]root.Data
[NBF]root.Data-preview.png
shHb
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙