Suspicious
Suspect

PE Executable
MD5: b737f037e7ccc74ed15dfa4544718a93
Size: 980.48 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b737f037e7ccc74ed15dfa4544718a93
Sha1 8f21d9db90644ee2dac90407f6d8aa94f45dddd9
Sha256 3a314ab3e162a1d14105a5a2f6116c461c8a69d9cf614f79521aed9effa61385
Sha384 82ff694efb57d98c51b13f2ea04e4fd4cd3ec98ed081650e43eaa5bc43aae241d62a81447f0d4ac443d3fc1ea3879a7a
Sha512 e96349ca04f226e89935e62a5e51f68e77d3223299ae575a3f3680e197b8ee961a8205854b368a69ebad53e34c3df2038d26c20c979e6c364857c5f61c06bf7b
SSDeep 24576:YgDft7WjU8CKAde2FbW1LddPY5Ah47tzXp9XKs:YgDfti/CKAo2FIb07tz/Ks
TLSH 702522E47290E853F9A497F205B0E37063345FA9D403D1928FDEACDFBA42B225E95391
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SudokuPlay.FormMenu.resources
SudokuPlay.Properties.Resources.resources
NH
[NBF]root.Data
VIAbVC
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: gpSDUS.pdb
Module Name
gpSDUS.exe
Full Name
gpSDUS.exe
EntryPoint
System.Void SudokuPlay.Program::Main()
Scope Name
gpSDUS.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gpSDUS
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
114
Main Method
System.Void SudokuPlay.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SudokuPlay.FormMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SudokuPlay.FormMenu.resources
SudokuPlay.Properties.Resources.resources
NH
[NBF]root.Data
VIAbVC
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙