Suspicious
Suspect

PE Executable
MD5: 3b206ef37a980e40addcb184288f6421
Size: 487.94 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 3b206ef37a980e40addcb184288f6421
Sha1 e27c54ebe66568f6f438080db7b1a9b4ff23c598
Sha256 0be718f7b7a74c02cb6e13cf89c32e36e3385d3c8d6bf11459e8a43afafe4ab4
Sha384 7ad017fa114932b42abf423808167e786ef56c92c19e2b40a7a973c7b5e3c655f230797dd812b720729602be6b158907
Sha512 3ad0573cc824b321b6fc56cfd61ab38a9d730361a1e2274fc291c4a58e88c6a2f1440780441eb0e4e0610bc00da52a24b45e9c571be2d3744eb862820c5480e3
SSDeep 12288:/LURSkTqNc4YlYfBo1zKOxRGZTjSYL4X:QckTqXYUwKfT
TLSH 45A401A827998F37E4B957F22431F33153B96E4EB552CB568FDAACDB7012B011A40B13
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SlotMachine.SlotDisplay.resources
SlotMachine.Properties.Resources.resources
NH
[NBF]root.Data
SZOBlk
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: xfiirX.pdb
Module Name
xfiirX.exe
Full Name
xfiirX.exe
EntryPoint
System.Void SlotMachine.Program::Main()
Scope Name
xfiirX.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xfiirX
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
374
Main Method
System.Void SlotMachine.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void SlotMachine.SlotDisplay::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
SlotMachine.SlotDisplay.resources
SlotMachine.Properties.Resources.resources
NH
[NBF]root.Data
SZOBlk
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙