Suspicious
Suspect

344958520dedc1bced70dfadd9f76077

PE Executable
MD5: 344958520dedc1bced70dfadd9f76077
Size: 859.14 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 344958520dedc1bced70dfadd9f76077
Sha1 7a050b41129d349852c18e6375d25e9468ff8df8
Sha256 d274af0fcf513c3d489d40aeec5a69d7f3f09db26d5ac2a2c2fb65697259b3c0
Sha384 8ceb5b5a8c38f2a8376afd2bc2cd897f640337ba68481b78c12b65d50d7560bdcbe17f213f83bf04be42e7593d540c47
Sha512 4998b7fbf181bed9e10c713bf54dc2af14e74ca24f55d87d49cce56c09e5d8c74060d912f66020a7a9e8afb650ad7977ac5a322191f1e7734761aa52a56b23b3
SSDeep 12288:VZnB6AnuBi9/fFET5lwPO/mXkpd+8UH7V0tnvGRhX+6mAM0JnAyS74FoxoBQh4nv:7kYuBWf8wW/48UHZ0tnerG0ayD/BQinv
TLSH 4705DF4632549617C469BFB70473D63807B66E19A420E2094EDEBCEB3A73B53293724F
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MotorwayService.Formulaires.FormulaireAgencement.resources
MotorwayService.Properties.Resources.resources
LAEA
[NBF]root.Data
[NBF]root.Data-preview.png
ProjectedW
[NBF]root.Data
[NBF]root.Data-preview.png
Qi
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
sEeT.exe
Full Name
sEeT.exe
EntryPoint
System.Void MotorwayService.Programme::Main()
Scope Name
sEeT.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sEeT
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
319
Main Method
System.Void MotorwayService.Programme::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MotorwayService.Formulaires.FormulairePrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MotorwayService.Formulaires.FormulaireAgencement.resources
MotorwayService.Properties.Resources.resources
LAEA
[NBF]root.Data
[NBF]root.Data-preview.png
ProjectedW
[NBF]root.Data
[NBF]root.Data-preview.png
Qi
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙