Suspicious
Suspect

bc7760c146637e9a0884de829473e1fa

PE Executable
MD5: bc7760c146637e9a0884de829473e1fa
Size: 485.38 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 bc7760c146637e9a0884de829473e1fa
Sha1 7209779b091bdde48684e97238ac03acebb395a0
Sha256 be08a05534b1ce02b5ac8cdeb06fc3e456baee6093a2bd0425e666385600b846
Sha384 f773506d416b5af3d1c1adebf8b1016c4bacbd5e12af98604d6cce9757999c1acbc377086749c649a61bccdc92727475
Sha512 5fd3210883be3bbfe714d024cd67760258ad18451a6fedf6de340f2edfa374ae747f0e7f1f9a9d84efaf26fc4ed4fc035f8721d9b6246daf2ecdd0a7e81ad2c0
SSDeep 12288:6pcAJeCr5dhxhLULeqF7eYjKc45GsdZKl68Nf/1P1s:6pcAJ35lhLULph65/KlTTs
TLSH C4A4F0402AADEB06E0B61FF55974E1B407B4AE9CA435C30A9FD53EEF70B6B010A51793
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MazeSolver.Formularios.FormPrincipal.resources
MazeSolver.Properties.Resources.resources
Fast_Tot
[NBF]root.Data
[NBF]root.Data-preview.png
hHbF
[NBF]root.Data
[NBF]root.Data-preview.png
oO
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: TcLI.pdb
Module Name
TcLI.exe
Full Name
TcLI.exe
EntryPoint
System.Void MazeSolver.Program::Main()
Scope Name
TcLI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TcLI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
319
Main Method
System.Void MazeSolver.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MazeSolver.Formularios.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
TcLI.exe
Full Name
TcLI.exe
EntryPoint
System.Void MazeSolver.Program::Main()
Scope Name
TcLI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TcLI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
319
Main Method
System.Void MazeSolver.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void MazeSolver.Formularios.FormPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MazeSolver.Formularios.FormPrincipal.resources
MazeSolver.Properties.Resources.resources
Fast_Tot
[NBF]root.Data
[NBF]root.Data-preview.png
hHbF
[NBF]root.Data
[NBF]root.Data-preview.png
oO
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙