Suspicious
Suspect

PE Executable
MD5: b417f492a94b049c6bdaef52f6bcacbd
Size: 771.58 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b417f492a94b049c6bdaef52f6bcacbd
Sha1 45799404d6edda377e9620551b48767471874b93
Sha256 046ca2dc433d9474ce7222ad4f6c0aa89a3caaab42e6c3c76f260a6c2ff241c8
Sha384 e3d354cacbb3b8f1308f3d629ae52d7d04556362257f902d3c23e1fd19ec135a59e80f94cb79df798cfdd015038d3b4f
Sha512 cb4abcd13ea4f31b8fec9bf2625c4b925de29e72b899ea0a32a9e09ee35b2050f679669bf656d72bd670f3a44b561d1419f531bac7293267fb55a45388823617
SSDeep 12288:94dp9tc3wpoTom8kHy41yF/IuyZ3q9enNoUVv0d9QRPEfnYfMNLQIV5s:9w2XompvmJyBMUu8OfnYeLN5s
TLSH 4CF40114321AD902D0514FB55A72E3B41B696F9EF812C607EFCA7EEFB13AF501942362
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RockPaperScissors.MainForm.resources
RockPaperScissors.Properties.Resources.resources
FrGi
[NBF]root.Data
[NBF]root.Data-preview.png
SHT
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: oUVa.pdb
Module Name
oUVa.exe
Full Name
oUVa.exe
EntryPoint
System.Void RockPaperScissors.Program::Main()
Scope Name
oUVa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oUVa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
173
Main Method
System.Void RockPaperScissors.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RockPaperScissors.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
oUVa.exe
Full Name
oUVa.exe
EntryPoint
System.Void RockPaperScissors.Program::Main()
Scope Name
oUVa.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oUVa
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
173
Main Method
System.Void RockPaperScissors.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void RockPaperScissors.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
RockPaperScissors.MainForm.resources
RockPaperScissors.Properties.Resources.resources
FrGi
[NBF]root.Data
[NBF]root.Data-preview.png
SHT
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙