Suspicious
Suspect

605d10b4d19df337650259af081a87e9

PE Executable
MD5: 605d10b4d19df337650259af081a87e9
Size: 672.77 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 605d10b4d19df337650259af081a87e9
Sha1 9f4760973ab4cb4000c968b96d440466d8a78868
Sha256 dae47ed76de2cef73a060c73c57311c4e770a072ba9947f8c8f64b83455cd839
Sha384 7587464f167077a3fef6ac8edc5e0f6f6df49f7e0654bb383c8b7f40c3fd2e9d31875b86b2b3bd49f060eb3758f994fd
Sha512 678ae49a62833f3769f762320bb331df6eecf036a2d95da650d2d37656428f9403d12752aa5cf563e7a37d245fd24b767626b3df673a720aca5950f77fe43ca7
SSDeep 12288:n7WcqfSpLr9aFENBqTe9LvXWlFjJkALd96owhRIbyL/RcNW0LDnjHHtsWfquA:EULJOE2i97eFjJkARQHhRIOLRcLDnjio
TLSH 37E41245AB04D407C82447B40ABCF2755F799FEDB521EB128FEA6DEBF9B27009E04162
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
JuegoPong.Properties.Resources.resources
Arch
[NBF]root.Data
LOg_outd
[NBF]root.Data
[NBF]root.Data-preview.png
UtF
[NBF]root.Data
[NBF]root.Data-preview.png
logout
[NBF]root.Data
[NBF]root.Data-preview.png
logout_1
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: fWe.pdb
Module Name
fWe.exe
Full Name
fWe.exe
EntryPoint
System.Void JuegoPong.Program::Main()
Scope Name
fWe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
fWe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
74
Main Method
System.Void JuegoPong.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void JuegoPong.FormMenuPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
fWe.exe
Full Name
fWe.exe
EntryPoint
System.Void JuegoPong.Program::Main()
Scope Name
fWe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
fWe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
74
Main Method
System.Void JuegoPong.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void JuegoPong.FormMenuPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
JuegoPong.Properties.Resources.resources
Arch
[NBF]root.Data
LOg_outd
[NBF]root.Data
[NBF]root.Data-preview.png
UtF
[NBF]root.Data
[NBF]root.Data-preview.png
logout
[NBF]root.Data
[NBF]root.Data-preview.png
logout_1
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙