Suspicious
Suspect

4fef8581b198c27c37f06137df872d52

PE Executable
MD5: 4fef8581b198c27c37f06137df872d52
Size: 815.1 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 4fef8581b198c27c37f06137df872d52
Sha1 a4d3c3c8cfe0cf04e3de11277d27d211c8ad1b52
Sha256 712ca31e2937bf843579e0e782ac8bc33ae84b4d580a3c69aabd531ff416b5b8
Sha384 d94d1f059bb50c42615367956d2f6d0f8189804583172cd228db6c6ce14e7e845e7f6dfafcc7db493eebcdd90dbeaa8c
Sha512 00a1c9d4a232f2d32832f56dede41f1ff26f52a0c92c09730c432a5a61d9f54ca2b21fd0b10eb0246d9ac693cc777d09ac807f7a7a391acd01b09f5262afc752
SSDeep 12288:LaqWQ/COQ/KliT3qWALzeApIaF1+C4Ujk6Yz2OkqWkEd2/L8uHxoLqUfF1l:tCWigneWTF1+6Vh3qWKwuHZUfXl
TLSH AF0512562A68DF23E36B07F506E2E1B013FA5D4FE532C2084EC95DEF749AB245A15383
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TideRace.FormBeach.resources
TideRace.Properties.Resources.resources
Pun
[NBF]root.Data
wzTN
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
qVDP.exe
Full Name
qVDP.exe
EntryPoint
System.Void TideRace.Program::Main()
Scope Name
qVDP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qVDP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
234
Main Method
System.Void TideRace.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TideRace.FormBeach::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TideRace.FormBeach.resources
TideRace.Properties.Resources.resources
Pun
[NBF]root.Data
wzTN
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙