Suspicious
Suspect

89a3b05298cc2b1b7f26fe94d31f4a53

PE Executable
MD5: 89a3b05298cc2b1b7f26fe94d31f4a53
Size: 702.46 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 89a3b05298cc2b1b7f26fe94d31f4a53
Sha1 a2f763c67311b61cf44247bbe9ad7bebd63d0e61
Sha256 e40ed83719528313ef5d65bb1ab4db9226a5e3d7421863f3375d94243db78049
Sha384 23013cddea16ef30cd2b067ceec7f0acb0941d87297ad17c77a93ddc3a6ad2bbd583688d7716e6879fd211751167ffa6
Sha512 944a023d2fa45d8b26a736d192711d68107975ee8615b9106e0d6510e90840c8fdf48a7faf14133ccab5acce427810fb7e82cd7f0c336277b9526925f98a882e
SSDeep 12288:21eW7CyQANJ5oThs/BGbfphRlr671oCEZK7a5XA2iXUhltKCE:2eWOfANJmTD9hRW1oTqa53iXUDtKT
TLSH 8EE4F1646653C7C6C0E663FC9CB1DF78566B4EC86820DF39AADDBDAB3B252040DC0664
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ticTacToe.Form1.resources
$this.Icon
[NBF]root.IconData
htta
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Core.Properties.Resources.resources
hgdh
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: dTGb.pdb
Module Name
dTGb.exe
Full Name
dTGb.exe
EntryPoint
System.Void ticTacToe.Program::Main()
Scope Name
dTGb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dTGb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
155
Main Method
System.Void ticTacToe.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ticTacToe.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ticTacToe.Form1.resources
$this.Icon
[NBF]root.IconData
htta
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Core.Properties.Resources.resources
hgdh
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙