Suspicious
Suspect

PE Executable
MD5: f4cf3e2ac6ee8b6f07299f7ce42367ec
Size: 529.93 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 f4cf3e2ac6ee8b6f07299f7ce42367ec
Sha1 32b2bc5dda0e30f8728339f05e858bd06e20b6a4
Sha256 007cd810db2b95805793f8b38d89946479092c54385a4e127bb9dfe5512ade1c
Sha384 9d49523c4dd0080d9c2367576331859f527eef35f00babea113909651292cfa5461a1def8bf5d2f5b635cb69c04600d1
Sha512 265c940b2fa62ff5f2e6db9ce78b6074439eeafe8b47ce89d730232d08da7f1bfcb10c41ea340c9f75a9d35d52e9bf162774c1f4927f48fe3f9be5af9b68a124
SSDeep 12288:VOku9YVpbH8bhQB0wwAnzxgM9xRblQsFhan2dSkR:WE8bhQB0wPfZJfh
TLSH F0B4F19062D9E500E1F77F7019B4D37487BABD88AD30D20A5BE8BDEF7D66B005864362
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
hXYm
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x7E000 size 13832 bytes
Info
PDB Path: qZvt.pdb
Module Name
qZvt.exe
Full Name
qZvt.exe
EntryPoint
System.Void StudyGuide.Program::Main()
Scope Name
qZvt.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qZvt
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
101
Main Method
System.Void StudyGuide.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void StudyGuide.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
qZvt.exe
Full Name
qZvt.exe
EntryPoint
System.Void StudyGuide.Program::Main()
Scope Name
qZvt.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qZvt
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
101
Main Method
System.Void StudyGuide.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void StudyGuide.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
StudyGuide.Properties.Resources.resources
hXYm
[NBF]root.Data
[NBF]root.Data-preview.png
shu
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙