Suspicious
Suspect

d5361e257f5aaa7c59a798c0b30ed339

PE Executable
MD5: d5361e257f5aaa7c59a798c0b30ed339
Size: 471.55 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 d5361e257f5aaa7c59a798c0b30ed339
Sha1 32391075eae582782b661c0c0aa3de355ad6e018
Sha256 df1aa968ad27b4ba317ee036dd641f42f7e15047cc9c3465f3402eb8f9081ea1
Sha384 4e0fd0be3e1b3107edeea7a735db9782929a40f36bfab08f27e5ba5ee21d32ddfd032a70b7587c57ec991d0823cd3955
Sha512 954361c65499fb0de10a1531445659843386ef123913583f3fdd8f56d358b8ef2dd4cf471bf0e683632b2b99a1b15f0f868de1c00932f95347fab8572363d76e
SSDeep 12288:wYaAx5cNlwXVVLTncgpolLOJo3ttazwOqyUkf/1P1s:wTwF1cgpHJo3ttazw1kTs
TLSH 6EA4F195326DDF1BC02E1BF45860D17163B49EADA022E6138FEB3DCFB826B0145527A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TorneoPiedraPapelTijera.FormInicio.resources
TorneoPiedraPapelTijera.Properties.Resources.resources
YoOA
[NBF]root.Data
[NBF]root.Data-preview.png
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: rrhv.pdb
Module Name
rrhv.exe
Full Name
rrhv.exe
EntryPoint
System.Void TorneoPiedraPapelTijera.Program::Main()
Scope Name
rrhv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rrhv
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
317
Main Method
System.Void TorneoPiedraPapelTijera.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TorneoPiedraPapelTijera.FormInicio::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
rrhv.exe
Full Name
rrhv.exe
EntryPoint
System.Void TorneoPiedraPapelTijera.Program::Main()
Scope Name
rrhv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rrhv
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
317
Main Method
System.Void TorneoPiedraPapelTijera.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void TorneoPiedraPapelTijera.FormInicio::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
TorneoPiedraPapelTijera.FormInicio.resources
TorneoPiedraPapelTijera.Properties.Resources.resources
YoOA
[NBF]root.Data
[NBF]root.Data-preview.png
blackBack
[NBF]root.Data
[NBF]root.Data-preview.png
shp
[NBF]root.Data
whiteback
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙