Suspicious
Suspect

715f951238c863c13d219b9c8cff73b2

PE Executable
MD5: 715f951238c863c13d219b9c8cff73b2
Size: 595.97 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 715f951238c863c13d219b9c8cff73b2
Sha1 55d3262b59fe6742429927da774a7a626e656be2
Sha256 e754d67774ff854e5f55ff42cb501d22ecf5e8ea38d646d32da5140c8ec63e3a
Sha384 8e68fb03538cd6c2b89b33720102e1c9bdc4df77c6d6a41c88167e34eb25b871bb8968b088ea4e3e4f0df6cb644db582
Sha512 c462b381a69f202bed64c60430fe3d3b1ea6908bba54027c7da79f31c3bb790bfb1264f201d2dfcf375a5100ada91698c64a0c5b8f64783dd112c8b9344ba328
SSDeep 12288:kDDmqt9B7B/hl3JM/1pkmzqyCNx9d0xghALPWHzDk+GODDh:kfmQ1/hpJM/1HYx9o+rf
TLSH E7C4125537A5D41BD8B6A7312CB0F3F446793EE9E530C38B8BD85D9B7AA2E448C40362
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Form1.resources
$this.Icon
[NBF]root.IconData
Moon
[NBF]root.Data
Star_generator.Properties.Resources.resources
eqaT
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\SrZWmOkqQI\src\obj\Debug\oPGf.pdb
Module Name
oPGf.exe
Full Name
oPGf.exe
EntryPoint
System.Void Canada_Simulator.Program::Main()
Scope Name
oPGf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oPGf
Assembly Version
3.9.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
254
Main Method
System.Void Canada_Simulator.Program::Main()
Main IL Instruction Count
10
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Star_generator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::Menu()
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::FailSafe()
ret <null>
Module Name
oPGf.exe
Full Name
oPGf.exe
EntryPoint
System.Void Canada_Simulator.Program::Main()
Scope Name
oPGf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oPGf
Assembly Version
3.9.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
254
Main Method
System.Void Canada_Simulator.Program::Main()
Main IL Instruction Count
10
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Star_generator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::Menu()
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::FailSafe()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Form1.resources
$this.Icon
[NBF]root.IconData
Moon
[NBF]root.Data
Star_generator.Properties.Resources.resources
eqaT
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙