Suspicious
Suspect

PE Executable
MD5: 454c0f50b56df85436d75f071927bd36
Size: 680.96 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 454c0f50b56df85436d75f071927bd36
Sha1 b20c81f00fa0f6f80b345e28317d79672b89d989
Sha256 4d785c8d5b76df07f04f87f542e375b2ac96ff64f28b6282179a005d801d9c1d
Sha384 cdcdfacbec398150b31759634556277762293bfb9f816dbeb319da043913508d195492f05a8394fff06c9b1480082b38
Sha512 eb622d318b8c846776820f9effd815f5dbd813dd547c719a0f9da91e35e31fd440040b2c81df8d0174181d20bb8cb756d0a5b274dada779d457d8dc5f89f929d
SSDeep 12288:T64LAlkI42tAHOPe8hfxQyH+NlJy05KoZKZ4M7Fv7uUipa5ud2lrWsN/aPhO:CWw555HQJh5zMFz3iNcKQaPY
TLSH ACE401D13E396712DDB046319629DDBD82640E683015BED36AED7BDB3BD8310AA0CF12
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
JogoEngarrafamento.FormMenu.resources
JogoEngarrafamento.Properties.Resources.resources
LastGame
[NBF]root.Data
qOyW
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: AXhf.pdb
Module Name
AXhf.exe
Full Name
AXhf.exe
EntryPoint
System.Void JogoEngarrafamento.Program::Main()
Scope Name
AXhf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
AXhf
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
106
Main Method
System.Void JogoEngarrafamento.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void JogoEngarrafamento.FormMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
AXhf.exe
Full Name
AXhf.exe
EntryPoint
System.Void JogoEngarrafamento.Program::Main()
Scope Name
AXhf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
AXhf
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
106
Main Method
System.Void JogoEngarrafamento.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void JogoEngarrafamento.FormMenu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
JogoEngarrafamento.FormMenu.resources
JogoEngarrafamento.Properties.Resources.resources
LastGame
[NBF]root.Data
qOyW
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙