Suspicious
Suspect

PE Executable
MD5: 3ca76a29ac7aac080444ddca045fcb3e
Size: 753.66 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 3ca76a29ac7aac080444ddca045fcb3e
Sha1 edeed46f7c8eff67687ea5ae249b15b1fafe77d3
Sha256 51df7f6d8d41fd062005a300423afede86d60bd9da284edbeba922f7adea8be1
Sha384 467a47699e16b79785d50a3aecdf2b21fa6309883d337e16b64e11f2b70b5da5f397f1aadf0e34452db693ca5d3419fa
Sha512 418f7bef2ade71ca807cd691629b5a2b752865a0b8c3ad2f86ccff77ce46cc09237b57cd885d2afceab84d875e9a789a43f2337ed699d357ec60098f8cb17b3d
SSDeep 12288:Wc9nMcTAC5uDN9iTt3BI837M5dXWbCs+c1PL7MuG0OTMfw:WwANDb83BIFFUvf
TLSH 46F412D8265AEB46DAA167FD0971E23407B92DADE811C34A1FD53EEFB839F440C10693
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DiceSimulator.Forms.MainForm.resources
DiceSimulator.Properties.Resources.resources
Eqcu
[NBF]root.Data
[NBF]root.Data-preview.png
Hasenfresse_mit_Sonnenbrille
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
Strange_Thinking
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: vknK.pdb
Module Name
vknK.exe
Full Name
vknK.exe
EntryPoint
System.Void DiceSimulator.Program::Main()
Scope Name
vknK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vknK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
235
Main Method
System.Void DiceSimulator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DiceSimulator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
vknK.exe
Full Name
vknK.exe
EntryPoint
System.Void DiceSimulator.Program::Main()
Scope Name
vknK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vknK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
235
Main Method
System.Void DiceSimulator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DiceSimulator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DiceSimulator.Forms.MainForm.resources
DiceSimulator.Properties.Resources.resources
Eqcu
[NBF]root.Data
[NBF]root.Data-preview.png
Hasenfresse_mit_Sonnenbrille
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
Strange_Thinking
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙