Suspicious
Suspect

PE Executable
MD5: 8a5495e29233673675071106ecfda133
Size: 739.33 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 8a5495e29233673675071106ecfda133
Sha1 d6f5c382c8ad2e3b1022808f4bffbb7b03f49862
Sha256 b225beef2338636503b1d0e3f9d43ec35ff0e2d3b271904b4fcafe2c3bc48c01
Sha384 12b186f02b0aa9192a75a234271a70890000779fbc462005ff583333ac0567c1ef6f99fdde26dbc3e944876885664e76
Sha512 456072ea4495f32cdbc7a878e8c6af467742505d294e9ddcd4f04961ccd1c4d37bb84089adfad73428ec3e2c279169cf288b7cc9706ae0e7d19a33fcba311c52
SSDeep 12288:i6Qi4RLsYEs2PiYaKdWjG7f8z4IIBsOzde1E9AZHl7CR6myDpk3me0OW:XQ9RL6tPIcWq70jpOzM1pu6dDpe
TLSH C6F412980787CA07D5E60BB558A0E3B417B86FDD7410E34A5FDDACEB382270229947E7
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SudokuApp.Forms.PuzzleGridForm.resources
SudokuApp.Properties.Resources.resources
KQtF
[NBF]root.Data
[NBF]root.Data-preview.png
KS
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: Tuel.pdb
Module Name
Tuel.exe
Full Name
Tuel.exe
EntryPoint
System.Void SudokuApp.Program::Main()
Scope Name
Tuel.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Tuel
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
143
Main Method
System.Void SudokuApp.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SudokuApp.Forms.PuzzleGridForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SudokuApp.Forms.PuzzleGridForm.resources
SudokuApp.Properties.Resources.resources
KQtF
[NBF]root.Data
[NBF]root.Data-preview.png
KS
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙