Suspicious
Suspect

PE Executable
MD5: 7da131cfe3d909493dc4a8f134504451
Size: 757.25 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7da131cfe3d909493dc4a8f134504451
Sha1 3dfec414f4d3c38a1fd6b3800932c4a14549460d
Sha256 6c8a67ab3e8dd6a4cee51708117b3ee1c9c34aaa6dee3486413fe8e52f841ec7
Sha384 a0c20db5fecde69540bbabe31b1ed12eba5829806b4d4d1cdaa6efc85f7ded0d0169c295c17a62c97dce7893db54dae3
Sha512 2456098422c00e566e01943a2b82d93b10456f505b6149d55f562988faa1d8159680e79eb34290a38c921f13daecbeb5ad1682dfba069bc4750c5fb72f6f1bf5
SSDeep 12288:HpHQsecfg/2W1BPaDMVx5d+m9dTopXJljbfArMzlRvoSZfxBVn0V6gtShqZm:+seA+2WHhVX8m91gRbfx5RwMB5y6ymqY
TLSH DDF40298335AEE12E9B61FF00870D7B01378BE8EA801D20B5FF66CDFB8297656454653
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
LotterySimulation.Forms.MainForm.resources
LotterySimulation.Properties.Resources.resources
RayD
[NBF]root.Data
[NBF]root.Data-preview.png
msp
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: RurX.pdb
Module Name
RurX.exe
Full Name
RurX.exe
EntryPoint
System.Void LotterySimulation.Program::Main()
Scope Name
RurX.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RurX
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
271
Main Method
System.Void LotterySimulation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void LotterySimulation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
RurX.exe
Full Name
RurX.exe
EntryPoint
System.Void LotterySimulation.Program::Main()
Scope Name
RurX.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RurX
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
271
Main Method
System.Void LotterySimulation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void LotterySimulation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
LotterySimulation.Forms.MainForm.resources
LotterySimulation.Properties.Resources.resources
RayD
[NBF]root.Data
[NBF]root.Data-preview.png
msp
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙