Suspicious
Suspect

PE Executable
MD5: 395644b6d2c00401d1cb92ccfe5996eb
Size: 741.38 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 395644b6d2c00401d1cb92ccfe5996eb
Sha1 e29a41244404b4c360c6e520deaf218ce9d24370
Sha256 3d488c7e2ce30c599303d4fc4bdc43692f80cc7e5e6feb1993197d97503f7dc3
Sha384 dc31b483bedef8d6ceb1d9d79aa3f9549149b72e203437b4ac04c58d0fa31eefc2a59dbaf8a7182e7f251b6bc8ff492c
Sha512 eb6e5f0330740923307040ecbbbd0fee5cc75c7fc8457949f279309c93b44b2326b249723e4f2b8d55ea0c0d7a29c571929df56f5dc088b32a9eaddfe02abf71
SSDeep 12288:NJriISA9z8tqMV/KncChIMnekeY/rQSrSvir0JigADhzlca54EhZUCX:mISA9mlcnhtnedYzLSbigGzcaSEXN
TLSH 15F412A6126AC903D4990BF018B1E3F553BD5E9DB421C3179FDD7CEB393AB003A506A6
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordScrambleGame.DifficultyForm.resources
WordScrambleGame.Properties.Resources.resources
Lachen
[NBF]root.Data
[NBF]root.Data-preview.png
Like
[NBF]root.Data
[NBF]root.Data-preview.png
True
[NBF]root.Data
rTPd
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: vURg.pdb
Module Name
vURg.exe
Full Name
vURg.exe
EntryPoint
System.Void WordScrambleGame.Program::Main()
Scope Name
vURg.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vURg
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
167
Main Method
System.Void WordScrambleGame.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordScrambleGame.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordScrambleGame.DifficultyForm.resources
WordScrambleGame.Properties.Resources.resources
Lachen
[NBF]root.Data
[NBF]root.Data-preview.png
Like
[NBF]root.Data
[NBF]root.Data-preview.png
True
[NBF]root.Data
rTPd
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙