Suspicious
Suspect

34bfb454cdaddeb511671af6847d2548

PE Executable
MD5: 34bfb454cdaddeb511671af6847d2548
Size: 571.9 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 34bfb454cdaddeb511671af6847d2548
Sha1 6e44c7dcafb018bd208dded43aaa22687e5f5b4c
Sha256 d2145175ec56d72f977d672a3201631d5091d44ef841883c9714e50bd315fcae
Sha384 1e66f7a0a2ca1d8479b363683a1f16a0173bab41521e6bf016d4dcd4ac3553778a43439cc98b6babd88d6b6526229d6c
Sha512 b89fc0a7d865952b0c0a34e0393f28eed1c54992ecf7b76a632c2afe398b811a72d96aa8b409966b2d441b0ca6a328816879e9ae03ab7767a79b409c286ee177
SSDeep 12288:7WjJYNZ2QmqqFxo584hNHezmZphfaUc7Zw8/Q2DWSXBSM6zC:EYxmq5D2mZphLc7Zz42DWYSI
TLSH 44C412446364C627C9AA57B126F1F1BD03BCAE85B812E35A8FCCBDDB7632F151844263
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TetrominoFiller.Forms.MainMenuForm.resources
TetrominoFiller.Properties.Resources.resources
Ban_Hammer
[NBF]root.Data
[NBF]root.Data-preview.png
Blender
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
Verspielt
[NBF]root.Data
[NBF]root.Data-preview.png
Versteckt
[NBF]root.Data
[NBF]root.Data-preview.png
ltuk
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: USTD.pdb
Module Name
USTD.exe
Full Name
USTD.exe
EntryPoint
System.Void TetrominoFiller.Program::Main()
Scope Name
USTD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
USTD
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
172
Main Method
System.Void TetrominoFiller.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TetrominoFiller.Forms.MainMenuForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TetrominoFiller.Forms.MainMenuForm.resources
TetrominoFiller.Properties.Resources.resources
Ban_Hammer
[NBF]root.Data
[NBF]root.Data-preview.png
Blender
[NBF]root.Data
[NBF]root.Data-preview.png
Moon
[NBF]root.Data
Verspielt
[NBF]root.Data
[NBF]root.Data-preview.png
Versteckt
[NBF]root.Data
[NBF]root.Data-preview.png
ltuk
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙