Suspicious
Suspect

PE Executable
MD5: 90291338d407e732e08ee9af391c054e
Size: 475.65 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 90291338d407e732e08ee9af391c054e
Sha1 d410798c584016bab523cc3149001b5f0957e382
Sha256 2803fb8dfd94517a466f941b6367751e2029d8959775ad02f71acead9e7acd19
Sha384 1e25589352cd719291cf74eec279bdc72a98a50aac53c9bde8bf8378491134231decdff994d91f15df9cca813b46f71d
Sha512 afbce7ec8d0a2199c260e5a1914e8aa597c594a0adba5ac0dd7cca0a3b47bc19181fb204ffc08f34ee026a7c27886b1d819a95d130b48aa6deb2970cea79f415
SSDeep 12288:nQIV5CTcOOQ6gVDald33CcFdpUCztnWMl+CS49g:nN5CbOL3LrDztnWF4O
TLSH 0EA4F114222EDD07C5525FB00931E3B42FA86F9DE422D207DFDABEEBB436B541985382
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RockPaperScissors.MainForm.resources
RockPaperScissors.Properties.Resources.resources
SHT
[NBF]root.Data
vwXb
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: WFEr.pdb
Module Name
WFEr.exe
Full Name
WFEr.exe
EntryPoint
System.Void RockPaperScissors.Program::Main()
Scope Name
WFEr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WFEr
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
173
Main Method
System.Void RockPaperScissors.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RockPaperScissors.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
WFEr.exe
Full Name
WFEr.exe
EntryPoint
System.Void RockPaperScissors.Program::Main()
Scope Name
WFEr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WFEr
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
173
Main Method
System.Void RockPaperScissors.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RockPaperScissors.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RockPaperScissors.MainForm.resources
RockPaperScissors.Properties.Resources.resources
SHT
[NBF]root.Data
vwXb
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙