Suspicious
Suspect

PE Executable
MD5: 58b24c9990e9c8c999287bb7c5880977
Size: 751.1 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 58b24c9990e9c8c999287bb7c5880977
Sha1 7dd7c7be497cda8253f8826e2da858cbc9f099c0
Sha256 8925d70e07b4ecfa4193aaf2d3e72649a6d4795dc533c305208b181a38ad3213
Sha384 5d0e87f903264c4546d946ea8f8a1b39ff78aa429d5466ee14672dd9ab1c3b79c145fc5dc4983c72a6a381fbe2bef27b
Sha512 72aea9668f80e7dc136905c2b8fe8dbac54fa1f8ddae5a6e27b2f52693f49c88e5ffa42426e376e8324ae58317d10274f5585fe30b46ff9d31e2398da43036d1
SSDeep 12288:PynbbuZP1vdet/ntIM4lR5T6usq1CMtEyENN/GvcDG7oAT4YAmDXmj9:PynbSZy9tIvRxsxUA/G0ezLmR
TLSH BDF4022A29A384D2D0653FB48993C27849343FE65973C3DABFE53C9B3D348519113766
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
FrontEnd.MainForm.resources
$this.Icon
DQ
BackEndLibrary.Properties.Resources.resources
VBQH
Name Value
Module Name
STeh.exe
Full Name
STeh.exe
EntryPoint
System.Void FrontEnd.Program::Main()
Scope Name
STeh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
STeh
Assembly Version
25.174.802.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
228
Main Method
System.Void FrontEnd.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void FrontEnd.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
STeh.exe
Full Name
STeh.exe
EntryPoint
System.Void FrontEnd.Program::Main()
Scope Name
STeh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
STeh
Assembly Version
25.174.802.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
228
Main Method
System.Void FrontEnd.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void FrontEnd.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
FrontEnd.MainForm.resources
$this.Icon
DQ
BackEndLibrary.Properties.Resources.resources
VBQH
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
58b24c9990e9c8c999287bb7c5880977
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
58b24c9990e9c8c999287bb7c5880977
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙