Suspicious
Suspect

37e350948972a4be683db63e42755413

PE Executable
MD5: 37e350948972a4be683db63e42755413
Size: 718.85 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 37e350948972a4be683db63e42755413
Sha1 5a9a4117d404db622bd2f434dd76918d1a086631
Sha256 be7855cbace4c35a3525ee28c84ae6a84c3e0ae2c1862ec37627a33c4677cd85
Sha384 c0c93891d30adc82f5915c044a4c4b81227ed5b9810e5cd1539231ac72715888af8c1343b302ee8ee4c4dee4097610db
Sha512 a4234ea1cce7eb15aaf963f45dd785acd9bd088141f9f2650bce92d89c38784dce47173b88eab0b186abf157cc1eec3e3a56ca5030b717c83ce81e3f366b1d25
SSDeep 12288:10gKmjZcKa/ZhmsUHnsA+N/Cc+auAW449VTNAtiyTh5xi/XEeeec9cPKBsrL4lVH:QmCPhhgnWBCc+UWzAEAtiPle5cPEsrMW
TLSH 66E4124576A6E923D0AA0BF90A50C27453BE6FCCB811E7925FC5ACFF75E23291981703
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
PDwP.exe
Full Name
PDwP.exe
EntryPoint
System.Void SectorRepair.Program::Main()
Scope Name
PDwP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PDwP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
320
Main Method
System.Void SectorRepair.Program::Main()
Main IL Instruction Count
7
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void SectorRepair.Program::InitializeApplication()
newobj System.Void SectorRepair.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
PDwP.exe
Full Name
PDwP.exe
EntryPoint
System.Void SectorRepair.Program::Main()
Scope Name
PDwP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PDwP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
320
Main Method
System.Void SectorRepair.Program::Main()
Main IL Instruction Count
7
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void SectorRepair.Program::InitializeApplication()
newobj System.Void SectorRepair.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Embedded Resources UNKNWOWNsuspect
5huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
5huhuhuhu
37e350948972a4be683db63e42755413
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
37e350948972a4be683db63e42755413
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙