Suspicious
Suspect

PE Executable
MD5: 7df2b1280b93fb781ed8d1f2132906b4
Size: 707.58 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7df2b1280b93fb781ed8d1f2132906b4
Sha1 fcdd5f11b2b8d3c971f0da00b486ff91d3d8654b
Sha256 1dc09f8752fe77cf8a00c0ac8f21b9e6a17c258e6b68c44fb9e749cf713d6035
Sha384 1e41ed60bc1a8d3092da973ceaa01dba2a6ab956596fac7ffe4e2aceb76ecb5e7784302a661a3cb0c84060fbcce6950d
Sha512 9d8bc1835a75caf483b28c551edc9dc5be8e1d33f98fbd1f791bb29e5765dd7c53a1d868fe93c0eda051248e6599c228bee14b650e70346cfb0dbe98423a101d
SSDeep 12288:3QIV5agNMQ97BGPuVRpg/lpG+d+pdp+qDkWnAvNYbox13zUOl8CIrnI:3N5zNMQePuVelQcid0qDKNYWJ+U
TLSH 62E40118125EDA07E5624F711972E3B51F986FADE412D303DFC9BEEBB436B802984245
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RockPaperScissors.MainForm.resources
RockPaperScissors.Properties.Resources.resources
SHT
[NBF]root.Data
hwfU
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: brOx.pdb
Module Name
brOx.exe
Full Name
brOx.exe
EntryPoint
System.Void RockPaperScissors.Program::Main()
Scope Name
brOx.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
brOx
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
173
Main Method
System.Void RockPaperScissors.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RockPaperScissors.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
brOx.exe
Full Name
brOx.exe
EntryPoint
System.Void RockPaperScissors.Program::Main()
Scope Name
brOx.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
brOx
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
173
Main Method
System.Void RockPaperScissors.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RockPaperScissors.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RockPaperScissors.MainForm.resources
RockPaperScissors.Properties.Resources.resources
SHT
[NBF]root.Data
hwfU
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙