Suspicious
Suspect

2643d603d7ab8745978cd1ee44f18a39

PE Executable
MD5: 2643d603d7ab8745978cd1ee44f18a39
Size: 807.42 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2643d603d7ab8745978cd1ee44f18a39
Sha1 7d64a644d8a36da7188ed6ffd41e1db0cb9c35f1
Sha256 1c067af5665a62e9251484c94bd2e2cbc734f97cf1c7243f62199abfabf43d19
Sha384 68c5a6a311b5db707e2209836a3702bb5d874deaed74e94a1d570eaff3f92c87bef78cf085bdf3ba68be3311c60c374f
Sha512 dd5e633c3c64c7049635ebe97a01e3fdfb1bb0dcb218161fa38d15023e11ce2fc6b84b7060732b2288934c7681362293f2b842984a6425eb011c3b464c7a9144
SSDeep 12288:yJqLPgI38zYLcnhfR+u/VsJLjcIGDv/wksyR50CeidRV9gRKStRiHAkY9mc97BeZ:Dgk8G4+muhjCDv/wkspWfIZ/E9b0BeZ
TLSH CD051246675ADB13E6AB1FF819B3E8701374AEAEA521D2064FC5BCEB75337189804313
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TideRace.FormBeach.resources
TideRace.Properties.Resources.resources
Pun
[NBF]root.Data
VxCU
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

4 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
tzia.exe
Full Name
tzia.exe
EntryPoint
System.Void TideRace.Program::Main()
Scope Name
tzia.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tzia
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
234
Main Method
System.Void TideRace.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TideRace.FormBeach::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TideRace.FormBeach.resources
TideRace.Properties.Resources.resources
Pun
[NBF]root.Data
VxCU
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙