Suspicious
Suspect

PE Executable
MD5: dfac9045c13cd007bbadc487a4305092
Size: 685.57 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 dfac9045c13cd007bbadc487a4305092
Sha1 48c780e540a17f99c3b7e8f6a0604e482489ded9
Sha256 30d7b8019fbd65ff8e25ba109b663a6440f3f407a5e01a4bcddf7e7bef33eac4
Sha384 b78243d6403e49be247372bc18bb6fea08686472508c496900bd194f92925a54ef6c3a004298bc31a2993430a1b72bbd
Sha512 e5e6eb1b8bee2b830d020132d49802fed8783195731e2aa79eb6ce01e8fc768326f76ac3d6514fdf48a3ed1d6d18dc0fae531d77882360a47b586bf438ea5046
SSDeep 12288:rHKA4C/fXXKZDtX/3t+a/n6rwvUYmSyYKdLO7iiVUv9cQuR3Mz4WEC7:rHKA4MXXKbvdT6rwvUYXKLOF+v9cQE3K
TLSH 30E412043BBDCA12D1A57BF108B1E27423B0BD9ED925E6A94EC42CDF753BB810522767
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TextTools.Forms.MainForm.resources
TextTools.Properties.Resources.resources
Keuf
[NBF]root.Data
[NBF]root.Data-preview.png
Mars
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: hsux.pdb
Module Name
hsux.exe
Full Name
hsux.exe
EntryPoint
System.Void TextTools.Program::Main()
Scope Name
hsux.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hsux
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
204
Main Method
System.Void TextTools.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TextTools.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TextTools.Forms.MainForm.resources
TextTools.Properties.Resources.resources
Keuf
[NBF]root.Data
[NBF]root.Data-preview.png
Mars
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙