Suspicious
Suspect

PE Executable
MD5: d3aa9a66f9a62e32d66f691e09da1b89
Size: 673.79 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 d3aa9a66f9a62e32d66f691e09da1b89
Sha1 70a3f360b99f5dd05ad101f04e2f1b9d39139bf4
Sha256 9fa4c989bed0f16fb028c6308b80ddbfe06ecc0f4b66229f498388292fcd292a
Sha384 5b8a06b7a7fef7f9aaa5a739d6cef6818db00c663a432cf409d63f375e293f2abeecee1e2993e3247a408d3b4cb5db87
Sha512 04f6acabe60f4a8f55ea918a7bda1160bcf8914f85b4469561fe5a3aef49ea628566ada51b1d086c3e09b78ce09fba5d382207c71c5a4d0c48084ca036caf420
SSDeep 12288:BNCWcqfcHJd5KX1KXNus8MBaQ7GUU/gPV66AFh/4ol58K5cn:xUn4XU9usLGULPUzhL/X
TLSH F0E402689B04C956C8240B784AB5F2791BA54FEEB125E205CFEA7DEFFCB13115E08097
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
JuegoPong.Properties.Resources.resources
Arch
[NBF]root.Data
ClL
[NBF]root.Data
[NBF]root.Data-preview.png
LOg_outd
[NBF]root.Data
[NBF]root.Data-preview.png
logout
[NBF]root.Data
[NBF]root.Data-preview.png
logout_1
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ykq.pdb
Module Name
ykq.exe
Full Name
ykq.exe
EntryPoint
System.Void JuegoPong.Program::Main()
Scope Name
ykq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ykq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
74
Main Method
System.Void JuegoPong.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void JuegoPong.FormMenuPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
ykq.exe
Full Name
ykq.exe
EntryPoint
System.Void JuegoPong.Program::Main()
Scope Name
ykq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ykq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
74
Main Method
System.Void JuegoPong.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void JuegoPong.FormMenuPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
JuegoPong.Properties.Resources.resources
Arch
[NBF]root.Data
ClL
[NBF]root.Data
[NBF]root.Data-preview.png
LOg_outd
[NBF]root.Data
[NBF]root.Data-preview.png
logout
[NBF]root.Data
[NBF]root.Data-preview.png
logout_1
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙