Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
HTA_pharmacy.Form1.resources
HTA_pharmacy.Form3.resources
$this.AutoScaleDimensions
$this.ClientSize
$this.Margin
button1.Font
button1.Location
button1.Size
button2.Font
button2.Location
button3.Location
button3.Size
button4.Location
button4.Size
button5.Location
button6.Location
dataGridView1.Location
dataGridView1.Size
dateTimePicker1.Location
dateTimePicker1.Size
label1.Location
label1.Size
label3.Location
label3.Size
label4.Location
label4.Size
textBox1.Location
textBox1.Size
textBox2.Location
HTA_pharmacy.Properties.Resources.resources
FntB
[NBF]root.Data
[NBF]root.Data-preview.png
MR
[NBF]root.Data
Name Value
Module Name
tGwY.exe
Full Name
tGwY.exe
EntryPoint
System.Void HTA_pharmacy.Program::Main()
Scope Name
tGwY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tGwY
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
351
Main Method
System.Void HTA_pharmacy.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HTA_pharmacy.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
tGwY.exe
Full Name
tGwY.exe
EntryPoint
System.Void HTA_pharmacy.Program::Main()
Scope Name
tGwY.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tGwY
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
351
Main Method
System.Void HTA_pharmacy.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void HTA_pharmacy.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
PDB Path PATH
tGhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙