Suspicious
Suspect

78617f90f7cdcbd54891c1db1ef15ccb

PE Executable
MD5: 78617f90f7cdcbd54891c1db1ef15ccb
Size: 879.62 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 78617f90f7cdcbd54891c1db1ef15ccb
Sha1 e52dfd3d86947cd126ddea8fba61adcc91078bdc
Sha256 307bf7df1df445947a15b7fc5374688b8b6940dd0f4584bae712b2b044c3372c
Sha384 967a1a2f5f95a09e6428e890130a11c51249086d719c19f9f675c6ce4156762a475614b4a65bb9733891e9c7e880ebe7
Sha512 e9e811462daf2c6e297bf632768452e6deab6f3ef57280c161d44d5582961068baa5633749d43eee13263deb74609539dc87e8c9d23e0dce43b318686be38b28
SSDeep 24576:8Z3hytuTb9emgYGuoMcGQJCBfsWLqC8KBgYvX:3u/dgZMcHJCBfsWe2BD
TLSH 5F1501503399EA02D9A95BF04871F2B413703E98EE21D20B8EE9BDFB79367055D58393
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PestWind.Properties.Resources.resources
Map2026
[NBF]root.Data
desp
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
peug.exe
Full Name
peug.exe
EntryPoint
System.Void Pestwind.Program::Main()
Scope Name
peug.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
peug
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
435
Main Method
System.Void Pestwind.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Pestwind.HauptForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PestWind.Properties.Resources.resources
Map2026
[NBF]root.Data
desp
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙