Suspicious
Suspect

PE Executable
MD5: 4bc5f9da7f3424d79d6777a8ae8b381a
Size: 744.45 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 4bc5f9da7f3424d79d6777a8ae8b381a
Sha1 90c43ea50c7c2543c4fa632e34b22c9406ef020f
Sha256 8ec0ad44c95b1b7190a2fcae723d0189bc0c814e08244b974c0e9fe51b19bd03
Sha384 90bfcb9b3d4a584b38cf319575c27849a69ddcaacf3bfdcc8a14a0fe8930ee8be8577a825c121e454045086730b47926
Sha512 ed71dac5cfe5790f73f1ba61d4703d149bf49b9a835537324dd260e2764dd65526b54fac7d1da3789fc4bf883670b8211adb0872b08c93847abdd72f5f682645
SSDeep 12288:rwqYKABEZ8Wgt/zPYGD3YHr2xHQ58R/3GOuhjvwi64W2nJ3nVKxYDCxvqf/1P1sT:rwzKACmWg2r9A/2Owvw94zJ3VKWDTs
TLSH DAF41215B26DCB22C0366BF849B0D27013B55EBDB922D3179EEA6DCF7435B808646393
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TorneoPiedraPapelTijera.FormInicio.resources
TorneoPiedraPapelTijera.Properties.Resources.resources
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
cEGf
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: Ftwo.pdb
Module Name
Ftwo.exe
Full Name
Ftwo.exe
EntryPoint
System.Void TorneoPiedraPapelTijera.Program::Main()
Scope Name
Ftwo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ftwo
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
317
Main Method
System.Void TorneoPiedraPapelTijera.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TorneoPiedraPapelTijera.FormInicio::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
Ftwo.exe
Full Name
Ftwo.exe
EntryPoint
System.Void TorneoPiedraPapelTijera.Program::Main()
Scope Name
Ftwo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ftwo
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
317
Main Method
System.Void TorneoPiedraPapelTijera.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TorneoPiedraPapelTijera.FormInicio::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TorneoPiedraPapelTijera.FormInicio.resources
TorneoPiedraPapelTijera.Properties.Resources.resources
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
cEGf
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙