Suspicious
Suspect

PE Executable
MD5: 3ab745b4c4db4e23227459c72539f269
Size: 973.31 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 3ab745b4c4db4e23227459c72539f269
Sha1 61aaad1f90c326ee6139a1acabcbfe41af2b24ea
Sha256 5b9cdcd1d809773601f109a660dbf35096e6535a933445ceeb8d943322bb42f9
Sha384 3185798b40a2a71731fa065858c556081fbd76776fe117896b881368fd47e7852fc16aa004463a68c09d6f96c20ed893
Sha512 b2983246a777d55597ac1af5772836241fa5afc5aee6c8545da2031ed43d5a342a87fcfc6c91286d834922b8c0dddace697ec8fdbdcfca0668f34560cb6ac640
SSDeep 24576:GVyP1Bn6LbVImXA97an6Tm9YVv/J5UpIt5BorFQ:GBbWmXeanV9m5qIfB2Q
TLSH 95251219269EDD07D5A31BF45A70F2F543B8AFCDE812E2024ED66CDFB629B5049013A3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GiocoNim.FormGioco.resources
WindowsFormsApp3.Properties.Resources.resources
VY
[NBF]root.Data
image_706
[NBF]root.Data
[NBF]root.Data-preview.png
lFvJ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: KzPQ.pdb
Module Name
KzPQ.exe
Full Name
KzPQ.exe
EntryPoint
System.Void WindowsFormsApp3.Program::Main()
Scope Name
KzPQ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KzPQ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
271
Main Method
System.Void WindowsFormsApp3.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GiocoNim.FormGioco::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
KzPQ.exe
Full Name
KzPQ.exe
EntryPoint
System.Void WindowsFormsApp3.Program::Main()
Scope Name
KzPQ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KzPQ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
271
Main Method
System.Void WindowsFormsApp3.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void GiocoNim.FormGioco::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
GiocoNim.FormGioco.resources
WindowsFormsApp3.Properties.Resources.resources
VY
[NBF]root.Data
image_706
[NBF]root.Data
[NBF]root.Data-preview.png
lFvJ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙