Suspicious
Suspect

c24d3ed376a4dca1fe6bde6c42aed3c6

PE Executable
MD5: c24d3ed376a4dca1fe6bde6c42aed3c6
Size: 1.66 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 c24d3ed376a4dca1fe6bde6c42aed3c6
Sha1 d8add06c02ecda277c0e03fb3afb6063787e190f
Sha256 2988bb5811ea625948d61f441d45bffb97e4dd7cd48321c85daad62e802bce5f
Sha384 112eba58745149fd206f5a6d66ebb8c01dbb545f2d8ae7e5bc746252bea647ab87360822d47c13516ab832dd3a4b3466
Sha512 b21a3ab45acffb9ca80a32ff6001c323f6a6a6ffd5ff7f7c9c77064f00d84d8cdd19ce1657b8fdb8e4b5211a1946fa027ef15c61326a3fa763106467a239b89f
SSDeep 49152:lJTSpLnn8FFkByO7y002bEwX6Q/0rrUs:vTwnnAmD02tXRMP
TLSH 687523582A0AC617C9A547344E76F2F5673C5ED8D511C217AFFCBDEFB9AAE244C00282
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
SpaceFactoryTycoon.AA.resources
SpaceFactoryTycoon.Properties.Resources.resources
HLCQ
[NBF]root.Data
[NBF]root.Data-preview.png
TY
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\CUHqAkSQIe\src\obj\Debug\tTrI.pdb
Module Name
tTrI.exe
Full Name
tTrI.exe
EntryPoint
System.Void SpaceFactoryTycoon.Program::Main()
Scope Name
tTrI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tTrI
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
53
Main Method
System.Void SpaceFactoryTycoon.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpaceFactoryTycoon.UI.MasterControlDesk::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
tTrI.exe
Full Name
tTrI.exe
EntryPoint
System.Void SpaceFactoryTycoon.Program::Main()
Scope Name
tTrI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tTrI
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
53
Main Method
System.Void SpaceFactoryTycoon.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SpaceFactoryTycoon.UI.MasterControlDesk::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
SpaceFactoryTycoon.AA.resources
SpaceFactoryTycoon.Properties.Resources.resources
HLCQ
[NBF]root.Data
[NBF]root.Data-preview.png
TY
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙