Suspicious
Suspect

3524a8602a70a43f2c4136166b66044d

PE Executable
MD5: 3524a8602a70a43f2c4136166b66044d
Size: 902.66 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 3524a8602a70a43f2c4136166b66044d
Sha1 a647eed37aa29fd19a9eb1ef10f32cdcecaa7a93
Sha256 e401c37dcfe4433d2b0fdbe449f905554b5449d397eb18e2c78cca0b10dc113b
Sha384 cf76197539fe01e0b258684117e80f80110e08ca5fe9d9f9c293909875a2b37ae73eb1a31695e9977897a4a3fdfc4327
Sha512 97a02e794fc171dcd60f42856ad6d44f3897aafaace0437a5ea632a452160544bdd4606a063d02e560bf35bc6c8305cac067c94659a9ddc351ec8e6fa128a420
SSDeep 24576:QQny55wbMCCV9+TpeXH44zUyk35bdO7s0JZ:Qmy5mJC2TuNYyk3KdZ
TLSH A91522251219DF23E8A467F215B0E2B55BF81E0EE033D2539FEAACFBB9127494444B47
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordScramble.FormMenuPrincipale.resources
WordScramble.Properties.Resources.resources
IFr
[NBF]root.Data
[NBF]root.Data-preview.png
NH
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: PET.pdb
Module Name
PET.exe
Full Name
PET.exe
EntryPoint
System.Void WordScramble.Program::Main()
Scope Name
PET.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PET
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
238
Main Method
System.Void WordScramble.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordScramble.FormMenuPrincipale::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
PET.exe
Full Name
PET.exe
EntryPoint
System.Void WordScramble.Program::Main()
Scope Name
PET.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PET
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
238
Main Method
System.Void WordScramble.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordScramble.FormMenuPrincipale::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordScramble.FormMenuPrincipale.resources
WordScramble.Properties.Resources.resources
IFr
[NBF]root.Data
[NBF]root.Data-preview.png
NH
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙