Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: cbfbbda9c5f9abb566637d9447dc40ee
Size: 1.28 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 cbfbbda9c5f9abb566637d9447dc40ee
Sha1 858764d3ccaada09c4805b057b2be4df26bdf8a5
Sha256 99c6a7cffb112b1e7317601acbe137d21df605b662ae35f3d81806278e33285f
Sha384 104880f8e2d5c4910e764069ec0a035bbd81c1d8b53d9e570b5a660d613984e738ab7cba5ed8d87842045213a36fe9df
Sha512 a87b61c5c719d44ab73458b5a35af5162a32c0f9ae54c5763ed7f6d056d670b55c4b88c69bd51427167da359010fcf403638a1bfa701adf344d9a4fcd9792aa2
SSDeep 24576:nqj6fCHzbS1RBD0+zQn2SmS5mOWc8HocBTukHMLAq4YF:qj6KHfS9D8n2PSaDBTukn/Y
TLSH 2E4512985516C903CA584B742AB2F2B417785EEEE402D317AFDCBEFB7972A550C48383
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ChessAnalyze.Properties.Resources.resources
Square
[NBF]root.Data
uroTd
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: bwfot.pdb
Module Name
bwfot.exe
Full Name
bwfot.exe
EntryPoint
System.Void ChessAnalyzer.Programa::Main()
Scope Name
bwfot.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bwfot
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
301
Main Method
System.Void ChessAnalyzer.Programa::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void ChessAnalyzer.FormularioTabuleiro::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙