Suspicious
Suspect

PE Executable
MD5: f2ae05da4d772033fc43dadfb590db38
Size: 767.5 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 f2ae05da4d772033fc43dadfb590db38
Sha1 f0ac46284d0797513e704cbb875aee8c90581748
Sha256 b56e8431fa939f346a93b8e6178fa2eddeaa734c3e53b42cc7cd2edc087a07e2
Sha384 780739a3343c3909a89a17c5446917352dfc2c3ed74f39de1e79347d27b4eb9194dd9186a8dcf3651e3cb4ef3acaf2cd
Sha512 aa4babd578143580a5d5a95240f53d5e4b70f0aba8723cbc7063df624ad3acb12cf1378c5b8b93110ab8aa0222fe8e48f497942f175bd139283a9334fcc9d87c
SSDeep 12288:nKqOZQ8CoYqrjsSlWa/SlUIxhgcTp1wfQ1Rc/16nXyhd2K/CuBku7eHkR:KRQsYqf3Z/SCIxCcNnA/hdTku7z
TLSH 1CF4DF161F8D89D9D1F2CAF11933D2701E3C9EA49C56D232CED47FABF63E6608A06152
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HigurashiDaybreakConfig.FormConfig.resources
$this.Icon
[NBF]root.IconData
IO
[NBF]root.Data
HigurashiDaybreakConfig.FormMyConf.resources
HigurashiDaybreakLauncher.Properties.Resources.resources
QxJa
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xB8000 size 13832 bytes
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\bpbaZqrIQf\src\obj\Debug\Sbqy.pdb
Module Name
Sbqy.exe
Full Name
Sbqy.exe
EntryPoint
System.Void HigurashiDaybreakConfig.Program::Main()
Scope Name
Sbqy.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Sbqy
Assembly Version
2.9.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
100
Main Method
System.Void HigurashiDaybreakConfig.Program::Main()
Main IL Instruction Count
49
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HigurashiDaybreakConfig.FormConfig::.ctor()
stloc.0 <null>
newobj System.Void HigurashiDaybreakConfig.DXEnvironment::.ctor()
stloc.1 <null>
ldloc.1 <null>
callvirt System.String HigurashiDaybreakConfig.DXEnvironment::getGameLocation()
stloc.2 <null>
ldloc.2 <null>
ldstr 
call System.Boolean System.String::op_Equality(System.String,System.String)
stloc.3 <null>
ldloc.3 <null>
brfalse.s IL_0062: ldloc.2
nop <null>
ldstr Please set your game folder location.
ldstr Important
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String)
pop <null>
newobj System.Void HigurashiDaybreakConfig.FormMyConf::.ctor()
stloc.s V_4
ldloc.s V_4
ldloca.s V_1
callvirt System.Void HigurashiDaybreakConfig.FormMyConf::setConfig(HigurashiDaybreakConfig.DXEnvironment&)
nop <null>
ldloc.s V_4
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ldloc.1 <null>
callvirt System.String HigurashiDaybreakConfig.DXEnvironment::getGameLocation()
stloc.2 <null>
nop <null>
ldloc.2 <null>
ldstr 
call System.Boolean System.String::op_Inequality(System.String,System.String)
stloc.s V_5
ldloc.s V_5
brfalse.s IL_007C: ret
nop <null>
ldloc.2 <null>
call System.Void HigurashiDaybreakConfig.Program::startApp(System.String)
nop <null>
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HigurashiDaybreakConfig.FormConfig.resources
$this.Icon
[NBF]root.IconData
IO
[NBF]root.Data
HigurashiDaybreakConfig.FormMyConf.resources
HigurashiDaybreakLauncher.Properties.Resources.resources
QxJa
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙