Suspicious
Suspect

PE Executable
MD5: 444784696026384aa6d56d52798a74cf
Size: 879.11 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 444784696026384aa6d56d52798a74cf
Sha1 8c0fd9be5bde2e0de975d5daa5349bbd20e05862
Sha256 01936ea3ab14ecadbc3ab003a97f78fcc82cc70b9f1a093ebc997cb587049ac4
Sha384 5566e4e41cd941c5a17dfe61f4612ca4b145f066ac68c0b7bd19a168cc2016ca347ee7cf0b5f741f2f17765c86cba780
Sha512 e572caa32393fbc18a1fcb38569fb5b45e56748ecb37cd450f170bce86852737db015975f675901bb481bd2af9d29928887463e42659ec1ef754e5b3b0782ebc
SSDeep 24576:8yMUfMzTAWn7K/EWKA2rbl1y8l8wYKZc8+EsnB5y6ymqZykia:lM1Z7K/E9by08wlZc8+dnn8mMZ
TLSH 95150255261EFF12D8B50FF009B0D3B21379BE4AA511C34B5EEA7CDFB8297A02994253
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
LotterySimulation.Forms.MainForm.resources
LotterySimulation.Properties.Resources.resources
ZgXY
[NBF]root.Data
[NBF]root.Data-preview.png
msp
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xD3400 size 13832 bytes
Info
PDB Path: WNSI.pdb
Module Name
WNSI.exe
Full Name
WNSI.exe
EntryPoint
System.Void LotterySimulation.Program::Main()
Scope Name
WNSI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WNSI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
271
Main Method
System.Void LotterySimulation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void LotterySimulation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
WNSI.exe
Full Name
WNSI.exe
EntryPoint
System.Void LotterySimulation.Program::Main()
Scope Name
WNSI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WNSI
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
271
Main Method
System.Void LotterySimulation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void LotterySimulation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
LotterySimulation.Forms.MainForm.resources
LotterySimulation.Properties.Resources.resources
ZgXY
[NBF]root.Data
[NBF]root.Data-preview.png
msp
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙