Suspicious
Suspect

PE Executable
MD5: afb60b3cbd998e618625cc5951b23df0
Size: 757.76 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 afb60b3cbd998e618625cc5951b23df0
Sha1 b6915212790527510d5496a08448a570ab7f4269
Sha256 2e1f9fa5a6c36a0d70fae41f3b47733bb26ef51dd8d8131f948b2273aef1811d
Sha384 082790470c399cc78181cd7e72c6b63a3b7eaecb842e442175afe88fbeacdcea3dcbbd8995901649f184d881d40ce451
Sha512 6c5185951bb2239be3149d89bea078254055a3248f86971a8ddfdb02deed0ab9b532894c6ffb310e73070f1ad7ec9d7f070e6f39b768e7d35adb372b9338c913
SSDeep 12288:Zk8hauqPyCMIPBGz2ggos5eqr6WAsN5hdAMDjEQnbBGHGdzTuUVORfmz2OIW8mU1:GqaVyC5PVghBqr6W1sKhnl5VuUVg+KO5
TLSH 4FF41219124ADF03D0A70BF40661E2F957B8BFDD9922DA075FDB2DEFB852B4049407A2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
YahtzeeClone.FormGioco.resources
WindowsFormsApp2.Properties.Resources.resources
VY
[NBF]root.Data
bmguD
[NBF]root.Data
[NBF]root.Data-preview.png
image_516
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: vbRtl.pdb
Module Name
vbRtl.exe
Full Name
vbRtl.exe
EntryPoint
System.Void WindowsFormsApp2.Program::Main()
Scope Name
vbRtl.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vbRtl
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
262
Main Method
System.Void WindowsFormsApp2.Program::Main()
Main IL Instruction Count
11
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
ldstr x
newobj System.Void YahtzeeClone.FormGioco::.ctor(System.String)
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
vbRtl.exe
Full Name
vbRtl.exe
EntryPoint
System.Void WindowsFormsApp2.Program::Main()
Scope Name
vbRtl.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
vbRtl
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
262
Main Method
System.Void WindowsFormsApp2.Program::Main()
Main IL Instruction Count
11
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
ldstr x
newobj System.Void YahtzeeClone.FormGioco::.ctor(System.String)
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
YahtzeeClone.FormGioco.resources
WindowsFormsApp2.Properties.Resources.resources
VY
[NBF]root.Data
bmguD
[NBF]root.Data
[NBF]root.Data-preview.png
image_516
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙