Suspicious
Suspect

PE Executable
MD5: e59da04b96a70cf9f9edecb9e5d58b76
Size: 855.04 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 e59da04b96a70cf9f9edecb9e5d58b76
Sha1 35d8f1a3d6ae16af077a9adb0c891ff584505757
Sha256 6ef10a2b79a761a18c6351d623cc52ef989a6ab06b37fdb07f5fb473b1c05c2b
Sha384 8e386738b730154c67bf6f2326f7d8ec36b2a75316ef9a88a061c431ac13d9db825970f2c0dcdcf165d9a753afc3bffd
Sha512 374cad685800ab908d236876c002225fa678f5fc63573e945079ca00f48bf0bdfca07ed5524fbd0c2ceb9f31a76c33454ce8ba3b726df4c891eaf8e16c0cd434
SSDeep 12288:M1eW7CyQ/6eO5OYWTzPrEmVGVlq510I76OLPNF1Ehbz0ZoL0a3djTz+cXDSD:keWOfUaPTGe51IClF+1zmoLTvzRXDS
TLSH EF05F1546643CBD6C1C11BFC58B2EFB4127B4E98A810DF3E86DDBEAB3F266046D80255
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ticTacToe.Form1.resources
$this.Icon
[NBF]root.IconData
htta
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Core.Properties.Resources.resources
CRrP
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: spKw.pdb
Module Name
spKw.exe
Full Name
spKw.exe
EntryPoint
System.Void ticTacToe.Program::Main()
Scope Name
spKw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
spKw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
155
Main Method
System.Void ticTacToe.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ticTacToe.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ticTacToe.Form1.resources
$this.Icon
[NBF]root.IconData
htta
[NBF]root.Data
pictureBox1.Image
[NBF]root.Data
[NBF]root.Data-preview.png
Core.Properties.Resources.resources
CRrP
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙