Suspicious
Suspect

d1d3e8afe0229f6ce1f588c363a573d3

PE Executable
MD5: d1d3e8afe0229f6ce1f588c363a573d3
Size: 795.65 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 d1d3e8afe0229f6ce1f588c363a573d3
Sha1 4a7a7b962d0f94d3e522035531ae2d286c55478e
Sha256 c514d19df459390e07641bbccc3c43e427349a82e85f1b5296acb7ff4cd4a8d3
Sha384 69370e1bbac2914b3619575f37974e9721455eb18e07b6848f9875724ac4eceece40bc5107b2efcb7c2b82c2ab8e3b34
Sha512 7d90230648710b69cbff470729c6b782f24bb5a8c53287a1b70d3cab85466dafb0ceddbeb8fb6d8a4ff1db01cb910da6ae16c319ce19e4bf3635d616cb42091c
SSDeep 24576:Rst5+VcyNk2IA5OISKqVAmduErDi4ylo1nfMKk1:Rsj9yNkSOIipdHQGfMF
TLSH B4050124222ADA02D1628FF51E76E3F41B646FAAE816E303AFD27DDFB4367805544347
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
TravBot.Form1.resources
$this.Icon
[NBF]root.IconData
Timer_Cycle.TrayLocation
Timer_List.TrayLocation
squid
[NBF]root.Data
TravBot.UnmanagedCode.resources
TravBot.Properties.Resources.resources
izft
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\wqoovQPsZv\src\obj\Debug\xTrW.pdb
Module Name
xTrW.exe
Full Name
xTrW.exe
EntryPoint
System.Void TravBot.Program::Main()
Scope Name
xTrW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xTrW
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
300
Main Method
System.Void TravBot.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TravBot.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
TravBot.Form1.resources
$this.Icon
[NBF]root.IconData
Timer_Cycle.TrayLocation
Timer_List.TrayLocation
squid
[NBF]root.Data
TravBot.UnmanagedCode.resources
TravBot.Properties.Resources.resources
izft
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙