Suspicious
Suspect

edaedafabfa469ed79b73b350315d1b2

PE Executable
MD5: edaedafabfa469ed79b73b350315d1b2
Size: 859.65 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 edaedafabfa469ed79b73b350315d1b2
Sha1 6a6ad0a1f4daa1a437e2269a44122fb979cc535b
Sha256 187aa13d50ceea33ab4aac1a72c02bcd248ca065901e71bf5ae2941ffaa0a046
Sha384 85aa6154908f7982dc8751e6774b9dd2052d183d5ff62086b3e88abb228e708c7a1e758706742f9d4555a16ae63f9962
Sha512 7bc5dc25b9555f82b3ac84c7f55ffb2ddd9e38253f55caf690ac0b66a56c45a880d82f9b05217416c54b9ccfb97df83e93958b77c2c8f2ca97f09cd97a54487a
SSDeep 24576:sQR+io0hWFHeTESrjSnVma5QBE0xF5coY/1:sQRa0SH3uA/5Lqy/1
TLSH 7B05F11833A6D906D5655FB80C71E3B54FB52E89E460D3139EFABEEFB936B045804283
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NestingBox.Properties.Resources.resources
Sed
[NBF]root.Data
zyHk
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
kqtp.exe
Full Name
kqtp.exe
EntryPoint
System.Void NestingBox.Program::Main()
Scope Name
kqtp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kqtp
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Info
PE Detect: PeReader OK (file layout)
Total Strings
321
Main Method
System.Void NestingBox.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NestingBox.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
kqtp.exe
Full Name
kqtp.exe
EntryPoint
System.Void NestingBox.Program::Main()
Scope Name
kqtp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kqtp
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
321
Main Method
System.Void NestingBox.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NestingBox.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NestingBox.Properties.Resources.resources
Sed
[NBF]root.Data
zyHk
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙