Suspicious
Suspect

4a0e5df2a7e55d6f90131636ec225465

PE Executable
MD5: 4a0e5df2a7e55d6f90131636ec225465
Size: 690.69 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 4a0e5df2a7e55d6f90131636ec225465
Sha1 15e7dd3c32d1abaab8638248a0953848d372d39e
Sha256 c18a28db58ee110d99668d90c2deede8ea10ba850799d8495ad7cd53488fb575
Sha384 44a42375e3c365faf20763e224137ccf78a4fc47200151c25a2cd507cb32e7934f7a60ee7f0c9ea336903aa922de56b9
Sha512 2f6cfda300f5aca22ce24c53c0d9806cc8cc582374ba0a68ec2e733a774ee965264b39509af4b760f9e3233d9765d7ba6af26ac4dc0f4602bbd3fa8ec371c940
SSDeep 12288:G+EvkfPlF3A1C1xBvuAcr+DhvseFVwG/fRlNU92NnyKuf/1P1s:G+zH3A1rATgi7WKuTs
TLSH BCE41205217DDF12D07B2BF459B0C57243B4AE9CB522D306DEE67DCBB826B414292BA3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TorneoPiedraPapelTijera.FormInicio.resources
TorneoPiedraPapelTijera.Properties.Resources.resources
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
dCdt
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: XxzH.pdb
Module Name
XxzH.exe
Full Name
XxzH.exe
EntryPoint
System.Void TorneoPiedraPapelTijera.Program::Main()
Scope Name
XxzH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XxzH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
317
Main Method
System.Void TorneoPiedraPapelTijera.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TorneoPiedraPapelTijera.FormInicio::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
XxzH.exe
Full Name
XxzH.exe
EntryPoint
System.Void TorneoPiedraPapelTijera.Program::Main()
Scope Name
XxzH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XxzH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
317
Main Method
System.Void TorneoPiedraPapelTijera.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TorneoPiedraPapelTijera.FormInicio::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TorneoPiedraPapelTijera.FormInicio.resources
TorneoPiedraPapelTijera.Properties.Resources.resources
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
dCdt
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙