Suspicious
Suspect

PE Executable
MD5: 33e4a094ea19adf93c29382dd8a9f0c1
Size: 729.6 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 33e4a094ea19adf93c29382dd8a9f0c1
Sha1 99672c71edffd10a1f1410ab7ef7b735b1a38012
Sha256 535d4a8cf82a5f7de2e7d506d67addfbfd0418b5e2d14f5f242482bba6b693c7
Sha384 d985c789402576daf1a5bce4c9da1305599cd76baaba12df83a9b87f65e9e609716250148e8def70dcc886c274ad316f
Sha512 b153a46abfb6cc38c7907685b431e1b278b9fea6691faff79db4d469d0837cdf9a503a253f26925944e67323640a51d23b3074afa4597e4f201b462c1f67d65b
SSDeep 12288:yGRi8ZS4wjwJmujlV5Z8GwIj5XIRvjeXKsS0PmTfwPZNjnevwvkQVI:3xawsujv5Zis5+bGKSPmzqZ5eovkKI
TLSH A7F41209BE38BF66D50C0B768163111080E78597B5F6F5AA6EED18D20936EC9C18FD8B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
pTEd.exe
Full Name
pTEd.exe
EntryPoint
System.Void SecureMode.Program::Main()
Scope Name
pTEd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pTEd
Assembly Version
1.6.1908.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
2
Main Method
System.Void SecureMode.Program::Main()
Main IL Instruction Count
21
Main IL
ldc.i4.2 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void SecureMode.ReliableForm18::Ⴀ()
ldc.i4 358
ldc.i4 323
call System.Void SecureMode.OptimizedForm56::Ⴐ(System.Int32,System.Char)
ldc.i4.0 <null>
ldc.i4 692
ldc.i4 723
call System.Void SecureMode.ProfessionalForm65::Ⴅ(System.Boolean,System.Int32,System.Int32)
ldc.i4.1 <null>
stloc.1 <null>
br.s IL_0002: ldloc.1
newobj System.Void SecureMode.ProfessionalForm53::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void SecureMode.Program::Main()
pop <null>
ret <null>
Module Name
pTEd.exe
Full Name
pTEd.exe
EntryPoint
System.Void SecureMode.Program::Main()
Scope Name
pTEd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pTEd
Assembly Version
1.6.1908.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
2
Main Method
System.Void SecureMode.Program::Main()
Main IL Instruction Count
21
Main IL
ldc.i4.2 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void SecureMode.ReliableForm18::Ⴀ()
ldc.i4 358
ldc.i4 323
call System.Void SecureMode.OptimizedForm56::Ⴐ(System.Int32,System.Char)
ldc.i4.0 <null>
ldc.i4 692
ldc.i4 723
call System.Void SecureMode.ProfessionalForm65::Ⴅ(System.Boolean,System.Int32,System.Int32)
ldc.i4.1 <null>
stloc.1 <null>
br.s IL_0002: ldloc.1
newobj System.Void SecureMode.ProfessionalForm53::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void SecureMode.Program::Main()
pop <null>
ret <null>
Embedded Resources UNKNWOWN
0huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWN
0huhuhuhu
33e4a094ea19adf93c29382dd8a9f0c1
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
33e4a094ea19adf93c29382dd8a9f0c1
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙