Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 905426cbc53f5a127addb0352997e974
Size: 4.15 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 905426cbc53f5a127addb0352997e974
Sha1 072633870bcb7b5f76eaad74a0a31ceb54038c11
Sha256 a46bec2031259cff4135b985d533e9c0bdb175603d61f031c227103bbb002a7b
Sha384 2069ffc46c5c39661d36c23fbfb628302bf6579e6634aa2ea6544d0654c5b01c659aee39b16dc5ee6f52c4b30a9ae614
Sha512 00495e0fa015f0fd41ad248c396541520d4829a1079a01dcb764f48be12253c17eb836327e14ae1fc148aeeb20dc649d051773388a70745021b2f6c510072615
SSDeep 98304:vjcADthjqXlbIaYs3da4986oss7ZE6bA2WmPIuQVsrb3h9LnXoSr:bbDthjkkaL3dae8TfEQopVsrLjYS
TLSH C31633682200C202C419567D95B1F7B8037C8DFFA911E227CFD4BCB7BABAB251E59257
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ChessAnalyze.Properties.Resources.resources
Square
[NBF]root.Data
psBWu
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: RZYOJ.pdb
Module Name
RZYOJ.exe
Full Name
RZYOJ.exe
EntryPoint
System.Void ChessAnalyzer.Programa::Main()
Scope Name
RZYOJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RZYOJ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
301
Main Method
System.Void ChessAnalyzer.Programa::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ChessAnalyzer.FormularioTabuleiro::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙