Suspicious
Suspect

PE Executable
MD5: 2bfa6a18586e533e579db4c1b78ef3c1
Size: 717.82 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 2bfa6a18586e533e579db4c1b78ef3c1
Sha1 e9e7d9da5c8d86cf50105617fad2c4671c03491b
Sha256 4824c73de2a144d3e4fbca50cb9fe2a81dda794258c6c9de45caf3572d17e145
Sha384 8bb7598a40a805956d2f8d145b7bab6d73ae4848be9f1017b5424515d12faf92fbb4ff51c89aed38871e3da3a49b517e
Sha512 4274e8677af193dfdc92e74eb96cbe7db25ce470723f4db80d30438db9231e03ce537390b036b0b946bedafcb93c02ca7a8255df4dcce6b1036221e0241d0cfa
SSDeep 12288:iRDDxtIxh25OybaDsn74P9pFgYkajcGvy0V8+OLD428q54l//IZW0R/PiwSnA9E:MDxR5dbaAnsNgYzcGvyKWLEI4RIkMzSY
TLSH 6BE412A5070AC913E5F503B529B1E3FC27696ECCB821E35B4FEAADDB383A3043951654
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NumberGuess.MainForm.resources
NumberGuess.Properties.Resources.resources
Ukew
[NBF]root.Data
[NBF]root.Data-preview.png
gap
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: CkCc.pdb
Module Name
CkCc.exe
Full Name
CkCc.exe
EntryPoint
System.Void NumberGuess.Program::Main()
Scope Name
CkCc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CkCc
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
102
Main Method
System.Void NumberGuess.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NumberGuess.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NumberGuess.MainForm.resources
NumberGuess.Properties.Resources.resources
Ukew
[NBF]root.Data
[NBF]root.Data-preview.png
gap
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙