Suspicious
Suspect

PE Executable
MD5: 196f56c0754230969680fd32b77c98e9
Size: 960.51 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 196f56c0754230969680fd32b77c98e9
Sha1 4d4ad54d012715d3284d9ea912af975659a3eb95
Sha256 614c73e3ef511dbd9960d6f2a412f62ce2d752e9e6ad426c2351eee8552861ff
Sha384 15e2639ab3bd1b33bf5181b9351ad0ef2b8301a81bbc04a111e07da33aca7fcfc7194aa6fe903a0682ba1228c9d983c9
Sha512 cea324b10a77e8f6470fa63056f2ca549ab050c884ce15eba294d9dc28a4caffcb23dcc54f9ee250e5a3f85b9786594095e6a90f21602edf501497b29d1f6633
SSDeep 24576:C07AfA4N9Grmd+ytQHfbOPpidrS27olXip9shDet:C0APN9GQ+yteqwRSTlip9ODe
TLSH 501512482311DA12D5A12BF51AB2F27803B93E9AE435D70B8EC9ADDFB576F509C44383
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SortingComparisons.Forms.AlgorithmSelectorForm.resources
SortingComparisons.Properties.Resources.resources
Eat_Other
[NBF]root.Data
[NBF]root.Data-preview.png
Oh
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
ZoKb
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: TacY.pdb
Module Name
TacY.exe
Full Name
TacY.exe
EntryPoint
System.Void SortingComparisons.Program::Main()
Scope Name
TacY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TacY
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
261
Main Method
System.Void SortingComparisons.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SortingComparisons.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SortingComparisons.Forms.AlgorithmSelectorForm.resources
SortingComparisons.Properties.Resources.resources
Eat_Other
[NBF]root.Data
[NBF]root.Data-preview.png
Oh
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
ZoKb
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙