Suspicious
Suspect

8d3f11c46fef0170fc4a814b4338ddd8

PE Executable
MD5: 8d3f11c46fef0170fc4a814b4338ddd8
Size: 870.91 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 8d3f11c46fef0170fc4a814b4338ddd8
Sha1 84d392e133b42d92b0e5c77c037e6793a7e349e1
Sha256 fea19e2a8ec0ae79fb6f25deec6ac647a53027ee3d4861be780daf205d49a718
Sha384 cdad744c7cf604863a5abe03d142b78fb7b94eeaaff6c3293b7e4c738d8fa8dc8c35cecc028e29ac610f2ed22af8cabd
Sha512 a8732e5c724b0e1ab80f307ee32b7ca45607ecbeb9f96d33cca2ada3cd594c2dcb040a870f71add899c643cf69d80facdbd0911d922e64c8a96669ab4ac13445
SSDeep 24576:1keWOfGwpDwOnKfvg3HPuTCD+USvXL4cKDj:0QGqDwO8g3HPbaKD
TLSH 9E0501A46653CBC2C1D617FD5CB0DF7816270E887821CF3A4AED7EAF3B262541D80669
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ticTacToe.Form1.resources
$this.Icon
[NBF]root.IconData
htta
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Core.Properties.Resources.resources
vOmD
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ATvc.pdb
Module Name
ATvc.exe
Full Name
ATvc.exe
EntryPoint
System.Void ticTacToe.Program::Main()
Scope Name
ATvc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ATvc
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
155
Main Method
System.Void ticTacToe.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ticTacToe.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ticTacToe.Form1.resources
$this.Icon
[NBF]root.IconData
htta
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Core.Properties.Resources.resources
vOmD
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙