Suspicious
Suspect

42129868bf93863f0f6ae5cbefbead0c

PE Executable
MD5: 42129868bf93863f0f6ae5cbefbead0c
Size: 833.02 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 42129868bf93863f0f6ae5cbefbead0c
Sha1 a47fd46af29ddf67fe12d3abadb651c3406778cd
Sha256 f6445ad9735732aa3ae46b05eeb7707cca1aa4e0fa4ad72e64de3d1c467d5121
Sha384 60379b1880bff97ae314d6ff43b5401a0ec059c78e52aca2d2836b1c5920fc5d0bf807d02afe6a089be48eb973ead5a7
Sha512 a38e9e173fb4140e28e6fa70dd05c0755eb5fca8ddd62bd405d4848be9182713a0e46b60c95f054071f569985c846490d8cdb4151a298f25175cc0e1aa5cbe32
SSDeep 24576:3JFkJsOmPyiLVLhDMDxcmsnB0VsAYit/r5Sr:oabnLVLYxcmsnB0eA9x
TLSH C905DF943FB4AEC1D9650BF10621EAF812B8AF9A1C24D39A7DDCBFDB7438B405454293
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
Name Value
Module Name
RucC.exe
Full Name
RucC.exe
EntryPoint
System.Void AtYarışıOyunu.Program::Main()
Scope Name
RucC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RucC
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
288
Main Method
System.Void AtYarışıOyunu.Program::Main()
Main IL Instruction Count
13
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AtYarışıOyunu.Form3::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
newobj System.Void AtYarışıOyunu.frm1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
RucC.exe
Full Name
RucC.exe
EntryPoint
System.Void AtYarışıOyunu.Program::Main()
Scope Name
RucC.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RucC
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
288
Main Method
System.Void AtYarışıOyunu.Program::Main()
Main IL Instruction Count
13
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void AtYarışıOyunu.Form3::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
newobj System.Void AtYarışıOyunu.frm1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
4huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
4huhuhuhu
42129868bf93863f0f6ae5cbefbead0c
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
42129868bf93863f0f6ae5cbefbead0c
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙