Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 178208eed7c95b5a0dd30d73396c2e9c
Size: 674.82 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 178208eed7c95b5a0dd30d73396c2e9c
Sha1 687db933129f99f33970387675190508eaa16882
Sha256 2eda62b3947c01aa4e3808dcf284d59a0e5abfc281c210fd2734d0f84add64c3
Sha384 15d41797002473d60f24d3d8a068e0dd0d03175b94d8390fd7dc1128b30fab482c739b3ca27ca3fbb0753d72495c8748
Sha512 ac4f15825711730a613f4fe900526f6abad3b9aa89ecb30ceddd286d71b71300ec3072d17e8ca6534ccf98f5446e73e66d52463fbb3dadfcc874c4fed2f7a94b
SSDeep 12288:d5WcqfeW8dpHnAlJVpcdlm35hF2iqU7JcRgnIDshqyid1kUAsh71W:8eWapHnAldulmJhyU7JcII9tAsNQ
TLSH 11E41214AE04D497CD2107B90B79E2F91B291FEEF620F31A5FE66DEFF822A114D08156
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ORe.pdb
Module Name
ORe.exe
Full Name
ORe.exe
EntryPoint
System.Void JuegoPong.Program::Main()
Scope Name
ORe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ORe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
74
Main Method
System.Void JuegoPong.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void JuegoPong.FormMenuPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ORe.exe
Full Name
ORe.exe
EntryPoint
System.Void JuegoPong.Program::Main()
Scope Name
ORe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ORe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
74
Main Method
System.Void JuegoPong.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void JuegoPong.FormMenuPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙