Suspicious
Suspect

PE Executable
MD5: 7339869ac9b65a7f9f455b92822ce0e2
Size: 768.51 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 7339869ac9b65a7f9f455b92822ce0e2
Sha1 475f0d4d2c7b3fc51d18f379ccf10701704f8380
Sha256 2f8315de575da924de5e72a06c9cf1957b00db3c471316ce5e4bc159cd91c0e7
Sha384 b5f1cff00d26a95fcc78539d998ab5fde7603a1d662e423bd8fd9f1d8c81d87d79d5159883e98b2c10f612d8db0e68c1
Sha512 ba20cbc9d01ffd915fbe7b176e8fc5ee1ae84e9adaa7893e426c6c21c65fec91498a80b032505465281db5b66614a007dbb2ddf2fb57ae228f11cbdebf18c4a6
SSDeep 12288:VxBq0C8ZY2vAEovZw+TMop451tkdDdLuH6Rwa5JlGE9sH28ddtxsV:amBApZw+v451uDxuH6maFGRW8J
TLSH 00F412A41759EE12C4A21FB81930E3F857B49EC8E811D343DAFAACEF7C2A75524543D2
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TetrisLite.Formularios.MenuPrincipal.resources
TetrisLite.Properties.Resources.resources
Pimp
[NBF]root.Data
[NBF]root.Data-preview.png
RH1
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: hapR.pdb
Module Name
hapR.exe
Full Name
hapR.exe
EntryPoint
System.Void TetrisLite.Program::Main()
Scope Name
hapR.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hapR
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
79
Main Method
System.Void TetrisLite.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TetrisLite.Formularios.MenuPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TetrisLite.Formularios.MenuPrincipal.resources
TetrisLite.Properties.Resources.resources
Pimp
[NBF]root.Data
[NBF]root.Data-preview.png
RH1
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙