Suspicious
Suspect

PE Executable
MD5: d0f8e4825d71bd4fd57a1a43a18bf9ae
Size: 708.1 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 d0f8e4825d71bd4fd57a1a43a18bf9ae
Sha1 ced9045d9f59ebc0ef32ded57fa52b634db9092b
Sha256 9732d3331728997cd38f78335e750cd134cfd8651f3c86abbefcaca44510dc7c
Sha384 e9bcdc8c5dd4d944f3a663d2950551a82bbe03dc8638433edf75d151cfefedd4c10ac19b9d49edde823c85f27823efa5
Sha512 040fb0cf830ebd8bcb5d5ed534e3d9daa553c22f39847166a96b70e6e5150233ffc96fc43a7c586006eac2b75f053ff8b91e4b6532690ab92e786421b015f5ec
SSDeep 12288:mQhhqh54yh4jfzolpL9hxzQ6kf2SMieyhBotm7Uhs97mUYgZ52s:mQu54yhGElHo6kxzeeBlKsdX
TLSH 60E4125462A6D823C5F657B02DB1F67407B97E6AA831E70A9FE57EEB3622F104D10303
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NimGame.MainMenuForm.resources
NimGame.Properties.Resources.resources
PIA
[NBF]root.Data
gtlC
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: VNpw.pdb
Module Name
VNpw.exe
Full Name
VNpw.exe
EntryPoint
System.Void NimGame.Program::Main()
Scope Name
VNpw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
VNpw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
231
Main Method
System.Void NimGame.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NimGame.MainMenuForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NimGame.MainMenuForm.resources
NimGame.Properties.Resources.resources
PIA
[NBF]root.Data
gtlC
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙