Suspicious
Suspect

PE Executable
MD5: 3ef8ad32dbc799f3413afbf9290bf727
Size: 915.46 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 3ef8ad32dbc799f3413afbf9290bf727
Sha1 17ffe3f50c4e13b7cee3b876595c2daff76feb11
Sha256 b114241cd4a768ac555cd281761b391f7fb88db242452814929512e1fccd64fd
Sha384 e23d8093125ffb895f9780013b6d314375b406234180c7c7615c1e82f46214282e568a0cdfcd6d50756378a36b317fee
Sha512 efb230a56ffd6ae11cdc2a4dbf39784920afc32d8d1f337b3e24efe6af0f6af820213ec989b0467e188dbe8a913f42f635e9842987ad89437e2c5a28bbcaadbc
SSDeep 24576:kjbt0FMZt0vg916XOcVJHGO2NGja8fFZUEA:emFMQvg9gXOumFEW8fF+E
TLSH 21151251A653CD06E5EB1BBD2B6AC67A1A311FCF5426C70E9FE27CA774B73810244342
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Private EXE Protector V2.30-V2.3X -> SetiSoft Team
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsApp51.StudentInfoForm.resources
WindowsFormsApp51.StudentsManagerForm.resources
$this.Icon
xsh
WindowsFormsApp51.Properties.Resources.resources
lrAO
Database.StudentsManagerModel.csdl
Database.StudentsManagerModel.msl
Database.StudentsManagerModel.ssdl
Name Value
Module Name
PNtr.exe
Full Name
PNtr.exe
EntryPoint
System.Void WindowsFormsApp51.Program::Main()
Scope Name
PNtr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PNtr
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
218
Main Method
System.Void WindowsFormsApp51.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WindowsFormsApp51.StudentsManagerForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
PNtr.exe
Full Name
PNtr.exe
EntryPoint
System.Void WindowsFormsApp51.Program::Main()
Scope Name
PNtr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
PNtr
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
218
Main Method
System.Void WindowsFormsApp51.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WindowsFormsApp51.StudentsManagerForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
PNhuhuhuhu
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
WindowsFormsApp51.StudentInfoForm.resources
WindowsFormsApp51.StudentsManagerForm.resources
$this.Icon
xsh
WindowsFormsApp51.Properties.Resources.resources
lrAO
Database.StudentsManagerModel.csdl
Database.StudentsManagerModel.msl
Database.StudentsManagerModel.ssdl
No malware configuration was found at this point.
PDB Path PATH
PNhuhuhuhu
3ef8ad32dbc799f3413afbf9290bf727
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
3ef8ad32dbc799f3413afbf9290bf727
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
3ef8ad32dbc799f3413afbf9290bf727
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙