Suspicious
Suspect

PE Executable
MD5: b5884edbb83c6d36b13e801bfa38fc53
Size: 1.1 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 b5884edbb83c6d36b13e801bfa38fc53
Sha1 c20b447daa7ee59bbaebef1841ccd1b2854abe0b
Sha256 ad35c23788b2e0f57f4a57326290de01f0680c567122ff11fa0eefe5443e522e
Sha384 b0a142c946403d6f4058dc2f8bd0806dd17db1e258a06fa71a1885ce817c17c8a1b186e6f6f86decc3199d36f9bb4071
Sha512 e95ae39622258c32553c91d63a12b16393a0ce91571aa1f1737f6773dd37bd948f1fa77ab9097fc1b1eec9b5a34096c49bbb624ccd222ebfefa0d738ef26e13f
SSDeep 24576:eSFOBOMNhpXucH5ZEBvJsDjfCueWRYl3BMJu:7FOBOMh5jEBTkA3OJu
TLSH 273501286288C409C9BF83B654B6D17543BABD27F934D36C4AC9ACEF3EB07425C55326
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AnalyzeGraphics.MainForm.resources
$this.Icon
[NBF]root.IconData
bindingNavigatorAddNewItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorDeleteItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveFirstItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveLastItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveNextItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMovePreviousItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
AnalyzeGraphics.Properties.Resources.resources
TCA
[NBF]root.Data
bddcp
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Module Name
TcAEy.exe
Full Name
TcAEy.exe
EntryPoint
System.Void AnalyzeGraphics.Program::Main()
Scope Name
TcAEy.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TcAEy
Assembly Version
4.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
760
Main Method
System.Void AnalyzeGraphics.Program::Main()
Main IL Instruction Count
37
Main IL
nop <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
ldnull <null>
ldftn System.Void AnalyzeGraphics.Program::Application_ThreadException(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
nop <null>
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void AnalyzeGraphics.Program::CurrentDomain_UnhandledException(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
nop <null>
newobj System.Void AnalyzeGraphics.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0069: ret
stloc.0 <null>
nop <null>
ldstr Critical error during application startup: 
ldloc.0 <null>
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
ldstr Application Error
ldc.i4.0 <null>
ldc.i4.s 16
call System.Windows.Forms.DialogResult System.Windows.Forms.MessageBox::Show(System.String,System.String,System.Windows.Forms.MessageBoxButtons,System.Windows.Forms.MessageBoxIcon)
pop <null>
nop <null>
leave.s IL_0069: ret
ret <null>
PDB Path PATH
TcAhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
AnalyzeGraphics.MainForm.resources
$this.Icon
[NBF]root.IconData
bindingNavigatorAddNewItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorDeleteItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveFirstItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveLastItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMoveNextItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
bindingNavigatorMovePreviousItem.Image
[NBF]root.Data
[NBF]root.Data-preview.png
AnalyzeGraphics.Properties.Resources.resources
TCA
[NBF]root.Data
bddcp
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
PDB Path PATH
TcAhuhuhuhu
b5884edbb83c6d36b13e801bfa38fc53
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙