Suspicious
Suspect

711277ac06842e909411226c2e04cc4f

PE Executable
MD5: 711277ac06842e909411226c2e04cc4f
Size: 687.1 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 711277ac06842e909411226c2e04cc4f
Sha1 01997ea2fe6cda38f49a3b8f3d97f888eca3d929
Sha256 bd17bb7ef1b86d6ee46268eb2779c9e7c2058deb907df45280ddc0ec6ecea41e
Sha384 5532c5c56ba292c910a6d6d98cdf40d99327796d3b0c00dd61bd2f1bfa82d2f7f82e7a2ec296a97681800ac0b18d207f
Sha512 dc10fb43bb3f7625cd3cc5921dba1d345146a2a3dc356d869e8b22bcbb9f849c90ff5e18b360a37777b7939b12d8ba51ed0ac1d3a876db531513c78e229301b2
SSDeep 12288:+AEIKdF34cg+yOqX4WesnJFK1Gfu1L92zioUOVYUDRSPYef/1P1s:uBJHvWesJmx92z6VTs
TLSH 13E40208262EDF16C0672FF45960D17117F8AEACB421D3478DFB6DDBB826B4046927A3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TorneoPiedraPapelTijera.FormInicio.resources
TorneoPiedraPapelTijera.Properties.Resources.resources
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
ltRY
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: KfPj.pdb
Module Name
KfPj.exe
Full Name
KfPj.exe
EntryPoint
System.Void TorneoPiedraPapelTijera.Program::Main()
Scope Name
KfPj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KfPj
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
317
Main Method
System.Void TorneoPiedraPapelTijera.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TorneoPiedraPapelTijera.FormInicio::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
KfPj.exe
Full Name
KfPj.exe
EntryPoint
System.Void TorneoPiedraPapelTijera.Program::Main()
Scope Name
KfPj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KfPj
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
317
Main Method
System.Void TorneoPiedraPapelTijera.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TorneoPiedraPapelTijera.FormInicio::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TorneoPiedraPapelTijera.FormInicio.resources
TorneoPiedraPapelTijera.Properties.Resources.resources
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
ltRY
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙