Suspicious
Suspect

PE Executable
MD5: ed18814dc98be58c08603369c725b730
Size: 857.09 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 ed18814dc98be58c08603369c725b730
Sha1 d01cdfbeb9d6bd3fb0d2446005c5596762ca54af
Sha256 769faad4d101ca7d2c112be380d8c23be716a5a4ba2febe06a0ecc38196fc2a2
Sha384 e0df2dc428241118f49c644dd19d2f9cc581e344e20ae3033248fa5009b91dba8ae475cf39583d68e7b2b9a012be014a
Sha512 71c4ce9072a3fc613e251de8eb8c57539b51fdf7063bd848e1002701072d32ddbf52d2c008700eabe7e23486a13106f3f7a16b4f47cb205f6d36ee0da1cb0235
SSDeep 24576:nLC41He/V153f+iU8MJPqyU1Rl98VwUfDPj:nLCcHenpXU8mPAlq/f
TLSH 6605F10DB2D19913E8B45AF44BA1E37203B15D8DA32ED7C64CD87DEBB2B5B132610A47
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Micro_ToolKit.About_Page.resources
Micro_ToolKit.Calculator.resources
$this.Icon
[NBF]root.IconData
FT
[NBF]root.Data
imageList1.TrayLocation
menuStrip1.TrayLocation
Micro_ToolKit.Form1.resources
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Micro_ToolKit.Main_Menu.resources
btn_Calculator.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btn_Convertor.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btn_Note.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btn_Reminder.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Micro_ToolKit.Properties.Resources.resources
vjln
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
qONG.exe
Full Name
qONG.exe
EntryPoint
System.Void Micro_ToolKit.Program::Main()
Scope Name
qONG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qONG
Assembly Version
0.8.5.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
396
Main Method
System.Void Micro_ToolKit.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Micro_ToolKit.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
qONG.exe
Full Name
qONG.exe
EntryPoint
System.Void Micro_ToolKit.Program::Main()
Scope Name
qONG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qONG
Assembly Version
0.8.5.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
396
Main Method
System.Void Micro_ToolKit.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Micro_ToolKit.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Micro_ToolKit.About_Page.resources
Micro_ToolKit.Calculator.resources
$this.Icon
[NBF]root.IconData
FT
[NBF]root.Data
imageList1.TrayLocation
menuStrip1.TrayLocation
Micro_ToolKit.Form1.resources
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Micro_ToolKit.Main_Menu.resources
btn_Calculator.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btn_Convertor.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btn_Note.Image
[NBF]root.Data
[NBF]root.Data-preview.png
btn_Reminder.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Micro_ToolKit.Properties.Resources.resources
vjln
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
ed18814dc98be58c08603369c725b730
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙