Suspicious
Suspect

PE Executable
MD5: 32b73fbaf8842e7f2e682ba768d842c2
Size: 833.02 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 32b73fbaf8842e7f2e682ba768d842c2
Sha1 72ac031474327589620ae5548168f1409f7002fe
Sha256 0070d70bb4e173624bbd845338dd8bcfff53b1566cbdf06e1973f7ccb69723ea
Sha384 ddee311b6c5cf742b436c6b043846fa7b56312851d8c581a693f0320a2fca426ab0a30e757eafaf46e69b4f3891933ad
Sha512 324a16ab76e1ad1aff92f036fb6342c30dc0b78238ccf28b92ca2401ad5c06a514c49b93201a10b0aa24c61b452d6273b3c8c779195978f6b17a327ab227bb9d
SSDeep 24576:1MiqGDTfvwuyDz2CXBcOQe7foco4BLgEH63FNf:1ZqGDDpyOwvZ5BLeVNf
TLSH 0F052364B3DAC307E9E61BF206BAD3B443382F8ED811C55B4BFE9CD778162198641762
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Checkers.MenuPrincipale.resources
Checkers.Properties.Resources.resources
NH
[NBF]root.Data
TYD
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: KhH.pdb
Module Name
KhH.exe
Full Name
KhH.exe
EntryPoint
System.Void Checkers.Program::Main()
Scope Name
KhH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KhH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
77
Main Method
System.Void Checkers.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Checkers.MenuPrincipale::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Checkers.MenuPrincipale.resources
Checkers.Properties.Resources.resources
NH
[NBF]root.Data
TYD
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙