Suspicious
Suspect

PE Executable
MD5: 84dbf83e72934ad14e9ca7660a63346e
Size: 593.92 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 84dbf83e72934ad14e9ca7660a63346e
Sha1 dae4ed745c1bb155417beea15cb06d5c7e5e0804
Sha256 42f5cbb12c4e13fb288fa434f31141d11f75f6a886623668d2d10f883dfc912b
Sha384 9e34113e02b86e229e7c094d3f37a847146a53dca7a20cef430e012a2909f7405940c7c3ce0511d43a5a3684ddd336e8
Sha512 c1994b80016368b3af183033351a592ec27ec035f692a303a1a50440905900d808c3bafaf52252c997ea38dd4342dc33fce27db6229e9df843005c4c44ebe5e8
SSDeep 12288:bgLmqXiNGERGk/yxydBWTqx+c1m9sqtYX0T3C:bImOq/yMdBV0YX0TS
TLSH 77C4125537B1E413DAF667790DB0F6B442B8BEDDEA20C34BDBD86D9B3966E158800302
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Form1.resources
$this.Icon
[NBF]root.IconData
Moon
[NBF]root.Data
Star_generator.Properties.Resources.resources
XCZd
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\yruNsoGsRl\src\obj\Debug\Kpeo.pdb
Module Name
Kpeo.exe
Full Name
Kpeo.exe
EntryPoint
System.Void Canada_Simulator.Program::Main()
Scope Name
Kpeo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Kpeo
Assembly Version
3.9.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
254
Main Method
System.Void Canada_Simulator.Program::Main()
Main IL Instruction Count
10
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Star_generator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::Menu()
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::FailSafe()
ret <null>
Module Name
Kpeo.exe
Full Name
Kpeo.exe
EntryPoint
System.Void Canada_Simulator.Program::Main()
Scope Name
Kpeo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Kpeo
Assembly Version
3.9.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
254
Main Method
System.Void Canada_Simulator.Program::Main()
Main IL Instruction Count
10
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Star_generator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::Menu()
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::FailSafe()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Form1.resources
$this.Icon
[NBF]root.IconData
Moon
[NBF]root.Data
Star_generator.Properties.Resources.resources
XCZd
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙