Suspicious
Suspect

19163f6e4d9fb38522ce2b61927ecc14

PE Executable
MD5: 19163f6e4d9fb38522ce2b61927ecc14
Size: 676.35 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 19163f6e4d9fb38522ce2b61927ecc14
Sha1 99eedc832ae9429fd5632e0fba441f022341c8e2
Sha256 c2f71c006d57414ecfcc0a9718779ae6f19c63ff7ef6738c4a5aa7c38e28d77e
Sha384 adca00ee8a9ed51eccbc45fe1d05ee9b55b0aba119ede100fcd5e3bc207e13f412d297ce6b3b37419f627e1772985c7f
Sha512 1fa43e8c7b9288a2002f97fb5e1edc2332db67fe20fed8ba5e8e57c8a0ee9b11cdf553e66691d40e1c5ca3822ded50feb60ff80d1fccf1f652aac3929694bb43
SSDeep 12288:9JriISA9HqOYFlQV/wWAThjt0BSNNIMq/P933ts0M8:2ISA9HF8WAltMSE9/PdC0M
TLSH 2FE413542256DD13E0E817F44CA0E7B973795ECEB821D3179ED86EEB383A7047A813A1
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordScrambleGame.DifficultyForm.resources
WordScrambleGame.Properties.Resources.resources
Lachen
[NBF]root.Data
[NBF]root.Data-preview.png
Like
[NBF]root.Data
[NBF]root.Data-preview.png
True
[NBF]root.Data
yjXE
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ozeW.pdb
Module Name
ozeW.exe
Full Name
ozeW.exe
EntryPoint
System.Void WordScrambleGame.Program::Main()
Scope Name
ozeW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ozeW
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
167
Main Method
System.Void WordScrambleGame.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordScrambleGame.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordScrambleGame.DifficultyForm.resources
WordScrambleGame.Properties.Resources.resources
Lachen
[NBF]root.Data
[NBF]root.Data-preview.png
Like
[NBF]root.Data
[NBF]root.Data-preview.png
True
[NBF]root.Data
yjXE
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙