Suspicious
Suspect

aa85991336ab9b73d7e5d2c7e5c1e310

PE Executable
MD5: aa85991336ab9b73d7e5d2c7e5c1e310
Size: 681.98 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 aa85991336ab9b73d7e5d2c7e5c1e310
Sha1 0246e2d43f06a6f3658bde34613371f807b4a1b3
Sha256 c6f69daf510c0bf05f45c8ef6e8ad79bb533fed15e4a1d5deef8b2dfea3708c9
Sha384 3d97e03e66b8af3d6260f376c315189677fee8adad5c7efb179f93287435e14db0193739e051a99516ee625f440c4c94
Sha512 f3c6325f493b4db6ec806faead234e830d45d5210a469c1a491c2032965a69d343ed04f3f07f8e526f8fcd4fd86cfab0c7f3cf01068de97fabfa6fa8bb4d671b
SSDeep 12288:PoFcWf+aRlahdWX1ya+ue49C+4TkYt7cciXFCnNAKpp25:Po3f+aDahy+uqD7FMFeNX25
TLSH B0E4226423E9EBA3E8E657F20872E27007B91E5D9532E2178FD9DCEFF5047264880752
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordScramble.FormMenuPrincipale.resources
WordScramble.Properties.Resources.resources
AaV
[NBF]root.Data
[NBF]root.Data-preview.png
NH
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: gxL.pdb
Module Name
gxL.exe
Full Name
gxL.exe
EntryPoint
System.Void WordScramble.Program::Main()
Scope Name
gxL.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gxL
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
238
Main Method
System.Void WordScramble.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordScramble.FormMenuPrincipale::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
gxL.exe
Full Name
gxL.exe
EntryPoint
System.Void WordScramble.Program::Main()
Scope Name
gxL.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gxL
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
238
Main Method
System.Void WordScramble.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void WordScramble.FormMenuPrincipale::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WordScramble.FormMenuPrincipale.resources
WordScramble.Properties.Resources.resources
AaV
[NBF]root.Data
[NBF]root.Data-preview.png
NH
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙