Suspicious
Suspect

bedeeefa188f9fea4f050848adcb3f0a

PE Executable
MD5: bedeeefa188f9fea4f050848adcb3f0a
Size: 1.05 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 bedeeefa188f9fea4f050848adcb3f0a
Sha1 be6714ad8e992e7ef38c3d5c61edfb73259bb64b
Sha256 a2fc3ab543e72decbea89ff3479cc9d813324bccccb291cba2536d95b0bdc64c
Sha384 e23b3caa45fcbfbbf40e0217579db6d39760af4acc9696f21031105ba1610d2b1c05248a4ec09b2ef1a511c76f64356f
Sha512 192fe03ebc5a050081947340e978d503dc6a580d3ccae2e20d71f8ade24bd9b817c708fb288892c15656d91f284364d8af5feabffc06d9db4d03b90832f602a4
SSDeep 24576:tmDo+iWIbymwZj4yaCc1oMyBFYwQjZO2vfUZ:tmDhINwlsCkoMA7avM
TLSH A82512666358FB26D8BE17B91632E23617F52D0EA921E328DEED7DEB7C117006C10243
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RescueStation.Properties.Resources.resources
Apollo
[NBF]root.Data
KwpF
[NBF]root.Data
[NBF]root.Data-preview.png
RescueStation.MainForma.resources
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
HWet.exe
Full Name
HWet.exe
EntryPoint
System.Void RescueStation.Program::Main()
Scope Name
HWet.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
HWet
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
329
Main Method
System.Void RescueStation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RescueStation.MainForma::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
HWet.exe
Full Name
HWet.exe
EntryPoint
System.Void RescueStation.Program::Main()
Scope Name
HWet.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
HWet
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
329
Main Method
System.Void RescueStation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RescueStation.MainForma::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RescueStation.Properties.Resources.resources
Apollo
[NBF]root.Data
KwpF
[NBF]root.Data
[NBF]root.Data-preview.png
RescueStation.MainForma.resources
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙