Suspicious
Suspect

PE Executable
MD5: ac16cff4e4146906295d233cea1d26be
Size: 490.5 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 ac16cff4e4146906295d233cea1d26be
Sha1 d990765721d2512bf9f69dec476fc4751497cf15
Sha256 ac1abdbe6b3e95b6096d53cd02cd8c7c7456a342f9cac0f13e4116a5d866a43a
Sha384 7364371deb4093427f8f2a44de8b80d350eb9224ef2cbf9b3d630ce6ff7797235bdcb0d692399421a94458806d044c12
Sha512 3bfe9fa29ed2e699661d788820166b4d8ab937b5d1b284afffa307444501daddf35f2e45e1e877554bd78b54cf47dc7d920500968e8d41cc7372cdb7c04f7ec2
SSDeep 12288:lOnmq09TyiNgrN5S5fhsqylHOOg29JLEDvlzI28o4a:limHYiNgrN05ZvylHOT2TL8FIA
TLSH 2CA4016867AAD403E9A6A7745DB1F27906397E8EEA30C34BDBC95CEFB521E504C40313
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Form1.resources
$this.Icon
[NBF]root.IconData
Moon
[NBF]root.Data
Star_generator.Properties.Resources.resources
ebAT
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\Client\Temp\LbZhKIgkHJ\src\obj\Debug\XOKw.pdb
Module Name
XOKw.exe
Full Name
XOKw.exe
EntryPoint
System.Void Canada_Simulator.Program::Main()
Scope Name
XOKw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XOKw
Assembly Version
3.9.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
254
Main Method
System.Void Canada_Simulator.Program::Main()
Main IL Instruction Count
10
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Star_generator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::Menu()
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::FailSafe()
ret <null>
Module Name
XOKw.exe
Full Name
XOKw.exe
EntryPoint
System.Void Canada_Simulator.Program::Main()
Scope Name
XOKw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XOKw
Assembly Version
3.9.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
254
Main Method
System.Void Canada_Simulator.Program::Main()
Main IL Instruction Count
10
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Star_generator.Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::Menu()
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::FailSafe()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0.exif
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Form1.resources
$this.Icon
[NBF]root.IconData
Moon
[NBF]root.Data
Star_generator.Properties.Resources.resources
ebAT
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙