Suspicious
Suspect

PE Executable
MD5: fcf2788e379180c2fd5520d29ac85750
Size: 938.5 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 fcf2788e379180c2fd5520d29ac85750
Sha1 3b971d495c06f617c5338629ec3335d98ebd3890
Sha256 3a8d95ebd1a116107405f1cb2a7d42e954643a9a0244ceef22a70b656b8525a3
Sha384 a87ec5257d8c4a7ee1ee68adc0b9823ebdb024c9279521d47f048d24f2f90cf63e5a556f3fe2669f2f70773c98526b3c
Sha512 05ca2ab64f3a9ef9b6b4eecb6ce379c2912ea5ac03ee9a886bbcc74c7f4e6bb8c5abfda7310e270ccd9413c58a85dc6097690933c8e0811216f5bbd50abc0be9
SSDeep 12288:DuglWehwa1/nkJsTmoEovAfVq91qWugPVhJp71H34lZL9heBCuUwfEC335m:lhJFkJsTmtoofo91o4Bd43
TLSH A715C3B12FE37981E42607F1FB4499BC123B9E864C148B87D584FA9B3DB7A9B410C572
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
Name Value
Module Name
bsQe.exe
Full Name
bsQe.exe
EntryPoint
System.Void AtYarışıOyunu.Program::Main()
Scope Name
bsQe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bsQe
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
288
Main Method
System.Void AtYarışıOyunu.Program::Main()
Main IL Instruction Count
13
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AtYarışıOyunu.Form3::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
newobj System.Void AtYarışıOyunu.frm1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
bsQe.exe
Full Name
bsQe.exe
EntryPoint
System.Void AtYarışıOyunu.Program::Main()
Scope Name
bsQe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bsQe
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
288
Main Method
System.Void AtYarışıOyunu.Program::Main()
Main IL Instruction Count
13
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AtYarışıOyunu.Form3::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
newobj System.Void AtYarışıOyunu.frm1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
4huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
4huhuhuhu
fcf2788e379180c2fd5520d29ac85750
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
fcf2788e379180c2fd5520d29ac85750
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙