Suspicious
Suspect

6ca812da2b3d606adfc0201e7faa0731

PE Executable
MD5: 6ca812da2b3d606adfc0201e7faa0731
Size: 833.02 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 6ca812da2b3d606adfc0201e7faa0731
Sha1 aa1b12d4d6c0582b96acba3c0a82f034f59ca840
Sha256 c844bfa1e91e52f2e75f131e9347d7f94b0618be6928f57fd0c09b6076c97ed0
Sha384 a212b4de228fa6c306b0898a507a6930d2a1ef3a3a37140bb0f69d14bc9be25c3113999b60529d72e2adb21b55558ef7
Sha512 7c631d88eacbc0793b4094d5d2b03b04ddf989af6a0d8d87bd37b6b70318bbecc289f8bd97480c677a4b96d10b562100004ec6056c10627ffc8fda826b077b39
SSDeep 24576:wN2OqhYBY2FSXp967cS4pu8CA2QaWe/Kgs/+8y:wwhYBY6SXp9kepu8L2QaZ/lN8y
TLSH 8C0501643778DE42E07F4BB00532C2B213B66D466162D3134FDB6CEBBD69B611AA46C3
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Tetris.HighScoresTable.resources
$this.Icon
[NBF]root.IconData
Tetris.Properties.Resources.resources
eng_flag
[NBF]root.Data
[NBF]root.Data-preview.png
rus_flag
[NBF]root.Data
[NBF]root.Data-preview.png
tuUi
[NBF]root.Data
[NBF]root.Data-preview.png
Tetris.Tetris.resources
DrawTimer.TrayLocation
GameOverTimer.TrayLocation
TimerGameFunc.TrayLocation
plus
[NBF]root.Data
Name Value
Module Name
TnOK.exe
Full Name
TnOK.exe
EntryPoint
System.Void Tetris.Program::Main()
Scope Name
TnOK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TnOK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
340
Main Method
System.Void Tetris.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Tetris.Tetris::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Tetris.HighScoresTable.resources
$this.Icon
[NBF]root.IconData
Tetris.Properties.Resources.resources
eng_flag
[NBF]root.Data
[NBF]root.Data-preview.png
rus_flag
[NBF]root.Data
[NBF]root.Data-preview.png
tuUi
[NBF]root.Data
[NBF]root.Data-preview.png
Tetris.Tetris.resources
DrawTimer.TrayLocation
GameOverTimer.TrayLocation
TimerGameFunc.TrayLocation
plus
[NBF]root.Data
No malware configuration was found at this point.
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
6ca812da2b3d606adfc0201e7faa0731
Embedded Resources UNKNWOWNsuspect
6huhuhuhu
6ca812da2b3d606adfc0201e7faa0731
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
6ca812da2b3d606adfc0201e7faa0731
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙