Suspicious
Suspect

fe5945419f54b7b16de89de0758f23c4

PE Executable
MD5: fe5945419f54b7b16de89de0758f23c4
Size: 1.05 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 fe5945419f54b7b16de89de0758f23c4
Sha1 f5f41d4072a9163bbceab9240fc286d679a8c3be
Sha256 da76eb3b0e04f01ce9df8f4501b4b8826fa332a486ae872cd7206ae8fc043901
Sha384 17038d74f069e23e1cf2d24834615303c0eeb2fcc82b7f1572a91ca00d28a207853222e7d7ba9dae7e03197bfeaf3f96
Sha512 30340233c3b34f218ac208abc1f0dafb42fda866a5ddc8babc7699709f4848d729ba48a28c934ee3d421029ab7ad3a4dce1007f2da9cf6f79a49e0831ed081fb
SSDeep 24576:t5daHIQnY5ekbArJ4bAvneWHcxJZtKxnNtXjHm:xUnYxbArqbAvnevZtKxLjHm
TLSH 1B25F16822A49E02D13D577945B1E37423F12C9B9416E30ADFD8FCEB3E21BE15D4A683
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QuantumAnalyzer.ShellExtension.bt_.resources
$this.Icon
[NBF]root.IconData
GM
[NBF]root.Data
QuantumAnalyzer.ShellExtension.Form2.resources
QuantumAnalyzer.ShellExtension.Properties.Resources.resources
dAhg
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Module Name
pavY.exe
Full Name
pavY.exe
EntryPoint
System.Void QuantumAnalyzer.ShellExtension.A::Main()
Scope Name
pavY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pavY
Assembly Version
0.0.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Info
PE Detect: PeReader OK (file layout)
Total Strings
1601
Info
PDB Path: ?
Main Method
System.Void QuantumAnalyzer.ShellExtension.A::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void QuantumAnalyzer.ShellExtension.bt_::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QuantumAnalyzer.ShellExtension.bt_.resources
$this.Icon
[NBF]root.IconData
GM
[NBF]root.Data
QuantumAnalyzer.ShellExtension.Form2.resources
QuantumAnalyzer.ShellExtension.Properties.Resources.resources
dAhg
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙