Suspicious
Suspect

PE Executable
MD5: 2736e27f8add019ea79d192b1beb4c6f
Size: 629.77 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 2736e27f8add019ea79d192b1beb4c6f
Sha1 c34ece30a2bb888ef8b14988997ec057030c13a5
Sha256 b4e1932f23a54390bc8743dfa8a7eea4c3e446eae0c97625d780988688274bf3
Sha384 1c66a66ca66114fc6112c461f50c5bd2b4cc1a45cff1d12c63ae83a85d81e88f3a72b27e38ff67b1679c32586d13cdaa
Sha512 93e7100032b5600961aec915e8263a40d4c7d06032d698b4d0094b2876ee80e9636ca876b90613ce5ec0f8285f6d9e909c1d031303af11258d6d6f56e1e0cf08
SSDeep 12288:Cbam5R9xHCakKLu45tmIg2rR7viKjv5sleCnCpthYvgSkR:Ua+DCj94XFrRJv5GCDXh
TLSH F1D4F1135968CB03F52497F12E73EA355BB23F5DA522D29E4DEB9CCBB910B014C88627
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ToursDeHanoi.FormPrincipal.resources
ToursDeHanoi.Properties.Resources.resources
NH
[NBF]root.Data
image_1832
[NBF]root.Data
[NBF]root.Data-preview.png
utTKw
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x96600 size 13832 bytes
Info
PDB Path: vSCNH.pdb
Module Name
vSCNH.exe
Full Name
vSCNH.exe
EntryPoint
System.Void ToursDeHanoi.Program::Main()
Scope Name
vSCNH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vSCNH
Assembly Version
201.502.607.709
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
298
Main Method
System.Void ToursDeHanoi.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ToursDeHanoi.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
vSCNH.exe
Full Name
vSCNH.exe
EntryPoint
System.Void ToursDeHanoi.Program::Main()
Scope Name
vSCNH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vSCNH
Assembly Version
201.502.607.709
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
298
Main Method
System.Void ToursDeHanoi.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ToursDeHanoi.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ToursDeHanoi.FormPrincipal.resources
ToursDeHanoi.Properties.Resources.resources
NH
[NBF]root.Data
image_1832
[NBF]root.Data
[NBF]root.Data-preview.png
utTKw
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙