Suspicious
Suspect

PE Executable
MD5: 136c040c8952e91c67af8bf1f3dcca8c
Size: 724.48 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 136c040c8952e91c67af8bf1f3dcca8c
Sha1 7844b2c69e04bb30629df43b4625bd67107d0530
Sha256 767ed906fd1e628e2e2df72fa7990a25ee9ea7cbdd4c1c2727d97b773962e061
Sha384 e6545f563db801cd67725a1506fea9287969173691bf8f999a064fb7fa11c4caf518faeca624230b1fb8936d61cea0a2
Sha512 71d5fdf4f38a952b51b4185ab8f72ac1c1c436285ff8f2419d51e2ff26e65dbaa6e66c7e3bf3046377d468804609f3ed40680997e15eae6375ff84f0230c8df8
SSDeep 12288:rWjaQr26zOeKJqmWFZ1dclVmo8jBEpEBfKUxnuF9EHsf+iURmqS:JQzOe0rGZR1jBEpEFKUxuz/CRmn
TLSH 07F412587246CA22C2A657B549B1F2B9077D6E9AB801F3075FDCBEEF7562F020C44263
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TetrominoFiller.Forms.MainMenuForm.resources
TetrominoFiller.Properties.Resources.resources
Ban_Hammer
[NBF]root.Data
[NBF]root.Data-preview.png
Blender
[NBF]root.Data
[NBF]root.Data-preview.png
EVGS
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
Verspielt
[NBF]root.Data
[NBF]root.Data-preview.png
Versteckt
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: dORH.pdb
Module Name
dORH.exe
Full Name
dORH.exe
EntryPoint
System.Void TetrominoFiller.Program::Main()
Scope Name
dORH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dORH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
172
Main Method
System.Void TetrominoFiller.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TetrominoFiller.Forms.MainMenuForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TetrominoFiller.Forms.MainMenuForm.resources
TetrominoFiller.Properties.Resources.resources
Ban_Hammer
[NBF]root.Data
[NBF]root.Data-preview.png
Blender
[NBF]root.Data
[NBF]root.Data-preview.png
EVGS
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
Verspielt
[NBF]root.Data
[NBF]root.Data-preview.png
Versteckt
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙