Suspicious
Suspect

PE Executable
MD5: 340a59f4e8e897c09780ac71ad3f3058
Size: 784.38 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 340a59f4e8e897c09780ac71ad3f3058
Sha1 2c0dea60ab051cd199cf07da56822cbc07f4ea53
Sha256 1102be281ceadcc5966ddd8ed9fb1fe436d920bbfcd376dd9ba252ab03d84c7b
Sha384 39211869c7788a7fbd434fc6cfc013a1a1603265211364c5b0e1ea8e4a00ebeec7113a16d3e1caa634557585f226c6cc
Sha512 6d8c5c467ccd151b71321b95916d29feecb5b66a0811be9ba4f6012f2d9c711e6e6d6b9b2c1554a9f005a2f709eb73473e495c618b263ba9ec6b9e08beafccf9
SSDeep 12288:FwJriISA9pMu0IiSULUDG1r/BJopglt+D5p8nAWKt0S+oxy98YuOgZyryoJ:fISA9JzUXBtnAWKqj8YGZyrXJ
TLSH 7BF40191A296CE03E5518BB90CD2F3B5733A9D9DB521C3528FD47DEB3E3A74528012B2
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordleForms.GameOver.resources
WordleForms.WordleForm.resources
$this.Icon
[NBF]root.IconData
True
[NBF]root.Data
statusStrip1.TrayLocation
toolStrip1.TrayLocation
WordleForms.Properties.Resources.resources
WiQE
[NBF]root.Data
[NBF]root.Data-preview.png
help_FILL0_wght300_GRAD0_opsz48
[NBF]root.Data
[NBF]root.Data-preview.png
restart
restart_alt_FILL0_wght400_GRAD0_opsz48
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
RNtZ.exe
Full Name
RNtZ.exe
EntryPoint
System.Void WordleForms.Program::Main()
Scope Name
RNtZ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RNtZ
Assembly Version
4.3.3.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
152
Main Method
System.Void WordleForms.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordleForms.WordleForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordleForms.GameOver.resources
WordleForms.WordleForm.resources
$this.Icon
[NBF]root.IconData
True
[NBF]root.Data
statusStrip1.TrayLocation
toolStrip1.TrayLocation
WordleForms.Properties.Resources.resources
WiQE
[NBF]root.Data
[NBF]root.Data-preview.png
help_FILL0_wght300_GRAD0_opsz48
[NBF]root.Data
[NBF]root.Data-preview.png
restart
restart_alt_FILL0_wght400_GRAD0_opsz48
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙