Suspicious
Suspect

4b63cdf002aa002b17c4bb9a15dc3aa2

PE Executable
MD5: 4b63cdf002aa002b17c4bb9a15dc3aa2
Size: 712.7 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 4b63cdf002aa002b17c4bb9a15dc3aa2
Sha1 805e453583f8f19197084581b1ea077e8013a936
Sha256 f9b5fed8925d4ce4c7cbb7e0d93f88f46ed2e7f7a755c7db0c01575ea3bc1544
Sha384 b04bd4f0521d7118aac39592f33009267b53494a62ea2d508a2c30ba4900d7e595954a376b7f2a6b0a1a3886c073f8d2
Sha512 7ba631a9acbb50148bf7353defdbf4170c5015c7bf2d3790d7774147132fbb0f53fc0de11b52e81d96de7152620c0d2f7362481c7bda12816ab0f26edfabd8ef
SSDeep 12288:GcVbQRLiGtYC5YJipSbQfeLHfTliJYo1OlMBzwRkJ4zbvCb:GchQRLpNObGyJxqOyBzYkv
TLSH 20E412583318D803C59206F55DB1F3B60BB86DA98511E7E6AFC87EEBB8E5F049C04693
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
matchingGame.Form1.resources
$this.Icon
[NBF]root.IconData
PIA
[NBF]root.Data
ofd1.TrayLocation
matchingGame.Properties.Resources.resources
fJhw
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\CJnEPryxPT\src\obj\Debug\Pila.pdb
Module Name
Pila.exe
Full Name
Pila.exe
EntryPoint
System.Void matchingGame.Program::Main()
Scope Name
Pila.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Pila
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
215
Main Method
System.Void matchingGame.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void matchingGame.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Pila.exe
Full Name
Pila.exe
EntryPoint
System.Void matchingGame.Program::Main()
Scope Name
Pila.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Pila
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
215
Main Method
System.Void matchingGame.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void matchingGame.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
matchingGame.Form1.resources
$this.Icon
[NBF]root.IconData
PIA
[NBF]root.Data
ofd1.TrayLocation
matchingGame.Properties.Resources.resources
fJhw
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙