Suspicious
Suspect

PE Executable
MD5: 0a081b803bf6c19f6021852af0782958
Size: 906.75 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 0a081b803bf6c19f6021852af0782958
Sha1 86a99268f10522ec806e370629e9053d76e83955
Sha256 8e70ded796554c6b4cacde8469bfc6cfc13b4adecdaf0e0e22b8fcfab89c8f19
Sha384 527447df537ba5037ca8d13d9af47c8f54f78a6feaffc07d9cae8986de8d5d3b6da6ece997d55da637a0ab47b85493f0
Sha512 bf2cb8a9319fa21eeca55539eba8e10d5a4409e1862dd57d4b37fed3ab7de722eb01f78f2b1ddb5fa61ee98af5e09d3af5e16b416adffb7927fa960bf3e99659
SSDeep 12288:weRBIBN389lMZF+qOr9ro9296S8oUGzHSlzaWPCNQG4qr9qR5DD5eNu+:RRBQ4Msro9U6SHUGzy+rNQk9qR1D5en
TLSH 32151204ED63A403F45452B74B91EAB973A80DACA4C1C2B17BF9EED775ADA014F63123
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
三鍵反應遊戲.Form1.resources
$this.Icon
[NBF]root.IconData
B6
[NBF]root.Data
countDown.TrayLocation
imageList1.TrayLocation
timeDelay.TrayLocation
timerGame.TrayLocation
HoqueLtd.Dashboard.resources
HoqueLtd.Properties.Resources.resources
YPp
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
ETA.exe
Full Name
ETA.exe
EntryPoint
System.Void HoqueLtd.Program::Main()
Scope Name
ETA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ETA
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
169
Main Method
System.Void HoqueLtd.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void HoqueLtd.HomePage::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
ETA.exe
Full Name
ETA.exe
EntryPoint
System.Void HoqueLtd.Program::Main()
Scope Name
ETA.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ETA
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
169
Main Method
System.Void HoqueLtd.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void HoqueLtd.HomePage::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
PDB Path PATH
?huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
三鍵反應遊戲.Form1.resources
$this.Icon
[NBF]root.IconData
B6
[NBF]root.Data
countDown.TrayLocation
imageList1.TrayLocation
timeDelay.TrayLocation
timerGame.TrayLocation
HoqueLtd.Dashboard.resources
HoqueLtd.Properties.Resources.resources
YPp
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
?huhuhuhu
0a081b803bf6c19f6021852af0782958
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙