Suspicious
Suspect

9333bb34844a2579ea99b40edd82e3fd

PE Executable
MD5: 9333bb34844a2579ea99b40edd82e3fd
Size: 1.1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 9333bb34844a2579ea99b40edd82e3fd
Sha1 b5511448afcb11e950db902a78b55c20993dc890
Sha256 3e1b1fe0edaa2aa1cd743646f41354eaaf7eaf54d47a416f141ba9f9320024fd
Sha384 992b0b9be1d2de02a96bace196d5c2cc2320bcd084cb54b288b6f28672902e9bec4618a904c87a4885bdf565e125e52f
Sha512 bf3a15717ad8e7ccc370cddbf82ddcf153e078618799435deaa81ebc06b5e68d28d1a8cde7ec1b59449f9dcc97bfa247e83fae9dacdb7663100c93c2366cc91f
SSDeep 24576:CjeA9s5wq82kRxCyOpAIu9JZutuT6z9WSj+oLEStE2FL:xUs5d8BxCyaYJctZj6D/CL
TLSH 9F351198A65EC913C89547B90E72FAB9277C2DEEE412D3064FEDACEB3566F004D04643
PeID
HQR data fileMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DewdropRelay.frmMain.resources
DewdropRelay.Properties.Resources.resources
TY
[NBF]root.Data
cYiu
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
TUOR.exe
Full Name
TUOR.exe
EntryPoint
System.Void DewdropRelay.Program::Main()
Scope Name
TUOR.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TUOR
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
310
Main Method
System.Void DewdropRelay.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DewdropRelay.frmMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
TUOR.exe
Full Name
TUOR.exe
EntryPoint
System.Void DewdropRelay.Program::Main()
Scope Name
TUOR.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TUOR
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
310
Main Method
System.Void DewdropRelay.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DewdropRelay.frmMain::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DewdropRelay.frmMain.resources
DewdropRelay.Properties.Resources.resources
TY
[NBF]root.Data
cYiu
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙