Suspicious
Suspect

a63036df2760437841dee3e8195ff04c

PE Executable
MD5: a63036df2760437841dee3e8195ff04c
Size: 663.55 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 a63036df2760437841dee3e8195ff04c
Sha1 323903d57a59b1cc91efe9c7abbdff333b38b09d
Sha256 e97f62d893c2f818f623482a0c8f35f32e9862a67cc479efdb5723ec75d1f6c0
Sha384 9cdb267f31211d388e76da76554f6fae2df5ac8ab210a852793afe2fe702a7fe03ce6ad2697abdaa21f2ae104b33f571
Sha512 2ff4ef0dedf83b71f0887e1fadd5966c0e3dc3adfae7cb303b1d22979bc2a9a5ebd5c3a1a3e7ef20f8be91b6d3c52b6f52a571dad05ac4c082ad51253d62b0b7
SSDeep 12288:ZpHVxBVn0V6gtShqZWaIUQOXT7xagYVprZQXI6qN2PWN0ylfGj1IVaxlS9avP:LB5y6ymqZCUfXT7xagYVXQDqN2U0ylfX
TLSH 2BE40189235AFF02D8B60BF01970E7B013B8AE5DA412D3568EFA6CDFB4397511898753
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
LotterySimulation.Forms.MainForm.resources
LotterySimulation.Properties.Resources.resources
msp
[NBF]root.Data
nklC
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: dVrV.pdb
Module Name
dVrV.exe
Full Name
dVrV.exe
EntryPoint
System.Void LotterySimulation.Program::Main()
Scope Name
dVrV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dVrV
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
271
Main Method
System.Void LotterySimulation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void LotterySimulation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
dVrV.exe
Full Name
dVrV.exe
EntryPoint
System.Void LotterySimulation.Program::Main()
Scope Name
dVrV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dVrV
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
271
Main Method
System.Void LotterySimulation.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void LotterySimulation.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
LotterySimulation.Forms.MainForm.resources
LotterySimulation.Properties.Resources.resources
msp
[NBF]root.Data
nklC
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙