Suspicious
Suspect

PE Executable
MD5: a416ad87c8f76375d8d5dac60cc0d976
Size: 1.1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 a416ad87c8f76375d8d5dac60cc0d976
Sha1 eb21f0ece0c5dfd14bfb3af59e2f86532d26fcf9
Sha256 9fec7314757f83b63eed9d9cbb0908d8d7291adf72e2f3fce4fe290afa9ece1a
Sha384 fdd8d567bf8a77b0ea6119fc589a6dbdcc2ff250ff531a254bcacc8b775701545b419dcc98c2365e84cc22e81e860010
Sha512 9d1fc46ff1fa6d6f2fda0572d663420cefec3124173676e03f2f40246d42030d935cf1d6a9afef53b9129d9f0ad86c03eaeb7fcda37a8d4a33c8abd664531e9e
SSDeep 12288:p1eW7CyQX09h+VSzjsqKI9kAk8alDOk0bMWxYw130mLggpcdBcJxDvsCUb:XeWOfX2jsqKFAp6ykMv130mMgO
TLSH 24359BF1A20385D9D4F704FDB979CD703093BD9D88908F1812DEAA5B77B23811C9AA5B
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ticTacToe.Form1.resources
$this.Icon
[NBF]root.IconData
htta
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Core.Properties.Resources.resources
ilto
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: axYj.pdb
Module Name
axYj.exe
Full Name
axYj.exe
EntryPoint
System.Void ticTacToe.Program::Main()
Scope Name
axYj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
axYj
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
155
Main Method
System.Void ticTacToe.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ticTacToe.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ticTacToe.Form1.resources
$this.Icon
[NBF]root.IconData
htta
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Core.Properties.Resources.resources
ilto
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙