Suspicious
Suspect

PE Executable
MD5: 08e4c97eb1a730634307d065ce6e2032
Size: 856.06 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 08e4c97eb1a730634307d065ce6e2032
Sha1 0682956eaffca53bedd0183cb4f36b5ac235950b
Sha256 07d9ea3efb31c16c6f58dbbfa380f267719f9ef565c2852215f2911a9bfbc42e
Sha384 0667eb308558d9d0a15d90478fd759340315f5f1fb5e612a2fc28dcf58045575afdd91e8a025561c1f719ed588c55f20
Sha512 ce6ec78e51dc35bd8cf6290d77edb5c7d13458568d259d83fc4fc595dcde34c362aff8833798fbc2b8e6ae76da01d3917d7ad7a26ae5fca9c6643d987d6bfe33
SSDeep 24576:apcAzYihmnV2+4A4OBHLbZFXBD7oULMWJhoIdTs:ZiuV2+fHLz58IM2hp
TLSH 440512502BADDB03E0B60FF06A35D17117757EA9A431C31A9FEA3ECBB465B010A513A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MazeSolver.Formularios.FormPrincipal.resources
MazeSolver.Properties.Resources.resources
Fast_Tot
[NBF]root.Data
[NBF]root.Data-preview.png
oO
[NBF]root.Data
[NBF]root.Data-preview.png
pOne
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: tZtA.pdb
Module Name
tZtA.exe
Full Name
tZtA.exe
EntryPoint
System.Void MazeSolver.Program::Main()
Scope Name
tZtA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tZtA
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
319
Main Method
System.Void MazeSolver.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MazeSolver.Formularios.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
tZtA.exe
Full Name
tZtA.exe
EntryPoint
System.Void MazeSolver.Program::Main()
Scope Name
tZtA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tZtA
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
319
Main Method
System.Void MazeSolver.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MazeSolver.Formularios.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MazeSolver.Formularios.FormPrincipal.resources
MazeSolver.Properties.Resources.resources
Fast_Tot
[NBF]root.Data
[NBF]root.Data-preview.png
oO
[NBF]root.Data
[NBF]root.Data-preview.png
pOne
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙