Suspicious
Suspect

PE Executable
MD5: 99260f7647b97c22974702b600e79c89
Size: 573.95 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 99260f7647b97c22974702b600e79c89
Sha1 9c83124088df8b65abe05fd560abd761ebae42b9
Sha256 41e4dd0218aed625e7883bd3dbe43a95796360bda2e2b7fcf020af9fe5e1f1dc
Sha384 664d21b45757e36a6edb34019830fdf07f59562788e7921a00b8b9d91bcaa04fab1b0f2c4310a99f04394165d2afeb06
Sha512 9b177ae6a9fe70c05ba67043548738f4e08497339771e41474201b5343b334c53912f7a9dde679d755907254cd9fa22bc02ca1d6c37724a6cf89bdba4614b4d5
SSDeep 12288:i9FascUCHqFEPdRTE3A8RovmM+jx1Ursmftxvw26NOhM3UtEPKDMtW:i9z6qA8Bwmj11MDvmNOhM3UtKT
TLSH 07C4224A2858D513C5D35FB908A1D33013FC6E1EEA2AC48A5FC57ECF792AB588A153D3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoinFlipSimulator.MainFlipForm.resources
CoinFlipSimulator.Properties.Resources.resources
SC
[NBF]root.Data
ujnZ
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: xBos.pdb
Module Name
xBos.exe
Full Name
xBos.exe
EntryPoint
System.Void CoinFlipSimulator.Program::Main()
Scope Name
xBos.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xBos
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
128
Main Method
System.Void CoinFlipSimulator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CoinFlipSimulator.MainFlipForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
xBos.exe
Full Name
xBos.exe
EntryPoint
System.Void CoinFlipSimulator.Program::Main()
Scope Name
xBos.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xBos
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
128
Main Method
System.Void CoinFlipSimulator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CoinFlipSimulator.MainFlipForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CoinFlipSimulator.MainFlipForm.resources
CoinFlipSimulator.Properties.Resources.resources
SC
[NBF]root.Data
ujnZ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙