Suspicious
Suspect

23efafd665e702da82193bf1bc5e630d

PE Executable
MD5: 23efafd665e702da82193bf1bc5e630d
Size: 1.58 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 23efafd665e702da82193bf1bc5e630d
Sha1 cfe8e8c12cf9aab112493a79eaee178cda83faa4
Sha256 2865456cb397aad9936aa001ea6a1d80b65862665c0e8a44dba7edda0c7e7589
Sha384 db2313d2a71c37d31133f1271e7a19c17870a4b161fc03bf9e36304f5cf9b00ccc8200e53cc45ae28164974ee40d1117
Sha512 344fa1f570ef44815dd454fc170abe98d747addce30662ef14a8a04bc6655c59e2ebdb496c82748f1c1dd74372c6e33bb3855a5c22b41cbda328815c86637695
SSDeep 49152:Bz9CzEUFiuBWi/VLdKinBF8miEAyrNo+NA:Bkz/zBWi/LKinBmmiEAyrNo+NA
TLSH 7075236A6269FF01D7AB5BF959B5E1716FB42C8E6521C3808FD92CFFB569B100A00703
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TideRace.FormBeach.resources
TideRace.Properties.Resources.resources
Pun
[NBF]root.Data
gJjv
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
PkZX.exe
Full Name
PkZX.exe
EntryPoint
System.Void TideRace.Program::Main()
Scope Name
PkZX.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PkZX
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
234
Main Method
System.Void TideRace.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TideRace.FormBeach::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TideRace.FormBeach.resources
TideRace.Properties.Resources.resources
Pun
[NBF]root.Data
gJjv
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙