Suspicious
Suspect

PE Executable
MD5: cf9ca1a410674e1af26582ca113f89b5
Size: 1.06 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 cf9ca1a410674e1af26582ca113f89b5
Sha1 115c629f2d16ac5cbd91f2aa3818ddc58baa6d25
Sha256 6712822d0051f3cf96949990caaf64dc9f9b0ed059d80fdfa040170dc2199cd5
Sha384 7a23f44ab5bb24349df6552193e8cfe34d9ab021025f7891888066e6d49547a85609c5bc47231cbff969aa390159f506
Sha512 51f1c7e96a632516b2741384940c85e0c8efb3b0288f0fdd8076cc1bb9544909e29564302f692a42de19b0f30e59187534e0364edc6fad3a7e20f2574cd2ad0b
SSDeep 24576:Nrl9QHc/ijyMqoiXaQwJ6JxNxqK9NS2THXNsxHP:9lKHNjZtinwJ6jOKNPRQ
TLSH EC35F1E83A31731ECD5289319A68ECB092A42DB971067AE355DF375B758C106EF0CF92
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PegSolitaire.StartMenuFormular.resources
PegSolitaire.Properties.Resources.resources
V6
[NBF]root.Data
ywDu
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
XCOH.exe
Full Name
XCOH.exe
EntryPoint
System.Void PegSolitaire.Program::Main()
Scope Name
XCOH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XCOH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
117
Main Method
System.Void PegSolitaire.Program::Main()
Main IL Instruction Count
37
Main IL
nop <null>
ldc.i4 -911357711
ldc.i4 -701203086
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.5 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0064: nop
ldc.i4.0 <null>
call System.Void PegSolitaire.Program::‏​​‌​‎​‍‏‫‬‫‭‍‌‬​‏‌‪‎‫‬‭‮(System.Boolean)
ldloc.0 <null>
ldc.i4 -22737909
mul <null>
ldc.i4 -2114972152
xor <null>
br.s IL_0006: ldc.i4 -701203086
nop <null>
ldloc.0 <null>
ldc.i4 -586980129
mul <null>
ldc.i4 -621340718
xor <null>
br.s IL_0006: ldc.i4 -701203086
call System.Void PegSolitaire.Program::‪‪‬‪​‪‎‪​‬‭​‬‏​‏‮‎‫‍‫‭‍‭‍‎‌‌‌‮‌‮()
ldloc.0 <null>
ldc.i4 297243078
mul <null>
ldc.i4 420346821
xor <null>
br.s IL_0006: ldc.i4 -701203086
nop <null>
newobj System.Void PegSolitaire.StartMenuFormular::.ctor()
call System.Void PegSolitaire.Program::‍‍‮‎‎‪‏‎‬‫‬​‍‪‪‮‏‫‮‎‮(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
XCOH.exe
Full Name
XCOH.exe
EntryPoint
System.Void PegSolitaire.Program::Main()
Scope Name
XCOH.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XCOH
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
117
Main Method
System.Void PegSolitaire.Program::Main()
Main IL Instruction Count
37
Main IL
nop <null>
ldc.i4 -911357711
ldc.i4 -701203086
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.5 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0064: nop
ldc.i4.0 <null>
call System.Void PegSolitaire.Program::‏​​‌​‎​‍‏‫‬‫‭‍‌‬​‏‌‪‎‫‬‭‮(System.Boolean)
ldloc.0 <null>
ldc.i4 -22737909
mul <null>
ldc.i4 -2114972152
xor <null>
br.s IL_0006: ldc.i4 -701203086
nop <null>
ldloc.0 <null>
ldc.i4 -586980129
mul <null>
ldc.i4 -621340718
xor <null>
br.s IL_0006: ldc.i4 -701203086
call System.Void PegSolitaire.Program::‪‪‬‪​‪‎‪​‬‭​‬‏​‏‮‎‫‍‫‭‍‭‍‎‌‌‌‮‌‮()
ldloc.0 <null>
ldc.i4 297243078
mul <null>
ldc.i4 420346821
xor <null>
br.s IL_0006: ldc.i4 -701203086
nop <null>
newobj System.Void PegSolitaire.StartMenuFormular::.ctor()
call System.Void PegSolitaire.Program::‍‍‮‎‎‪‏‎‬‫‬​‍‪‪‮‏‫‮‎‮(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
PegSolitaire.StartMenuFormular.resources
PegSolitaire.Properties.Resources.resources
V6
[NBF]root.Data
ywDu
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙