Suspicious
Suspect

PE Executable
MD5: cbfbbda9c5f9abb566637d9447dc40ee
Size: 1.28 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 cbfbbda9c5f9abb566637d9447dc40ee
Sha1 858764d3ccaada09c4805b057b2be4df26bdf8a5
Sha256 99c6a7cffb112b1e7317601acbe137d21df605b662ae35f3d81806278e33285f
Sha384 104880f8e2d5c4910e764069ec0a035bbd81c1d8b53d9e570b5a660d613984e738ab7cba5ed8d87842045213a36fe9df
Sha512 a87b61c5c719d44ab73458b5a35af5162a32c0f9ae54c5763ed7f6d056d670b55c4b88c69bd51427167da359010fcf403638a1bfa701adf344d9a4fcd9792aa2
SSDeep 24576:nqj6fCHzbS1RBD0+zQn2SmS5mOWc8HocBTukHMLAq4YF:qj6KHfS9D8n2PSaDBTukn/Y
TLSH 2E4512985516C903CA584B742AB2F2B417785EEEE402D317AFDCBEFB7972A550C48383
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ChessAnalyze.Properties.Resources.resources
Square
[NBF]root.Data
uroTd
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: bwfot.pdb
Module Name
bwfot.exe
Full Name
bwfot.exe
EntryPoint
System.Void ChessAnalyzer.Programa::Main()
Scope Name
bwfot.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bwfot
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
301
Main Method
System.Void ChessAnalyzer.Programa::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ChessAnalyzer.FormularioTabuleiro::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ChessAnalyze.Properties.Resources.resources
Square
[NBF]root.Data
uroTd
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙