Suspicious
Suspect

d7281aef799285c6307d2791bb8b6f1e

PE Executable
MD5: d7281aef799285c6307d2791bb8b6f1e
Size: 845.32 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 d7281aef799285c6307d2791bb8b6f1e
Sha1 0fa8344d6c0147e5e1a11c34f5af88e9c52c8433
Sha256 cc8d870cb3894eccc05026181ff7075493e0d29d71d0eae115e29bd682830930
Sha384 25f4891d317f3df5a2a54e9d1b3d5b7a4838e31992a45ebc8813c6487008569658a9c91409a9542639077e79f2f3f83e
Sha512 2c92c3cccacd093df07de1bbf18ac7229be38dbcc2223f0cd588b1a206143c4c08d67c5f343d41d820578bd52d3e56f9f0af356be0a78b75b2ea652b02b87bd5
SSDeep 24576:JxS0mZofJNKNE5incHi0bEWTYSYGFhwPB/8/fUT:K7Zo/KG4cToCY9EwPBKMT
TLSH B70501883660F14FC963A7319EB0ED70A6247DABA717C207A1D31D6F7A5D5D6CE002A3
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Form1.resources
$this.Icon
[NBF]root.IconData
Moon
[NBF]root.Data
Star_generator.Properties.Resources.resources
KnJi
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xCB000 size 13832 bytes
Module Name
xanm.exe
Full Name
xanm.exe
EntryPoint
System.Void Canada_Simulator.Program::Main()
Scope Name
xanm.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xanm
Assembly Version
3.9.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
254
Main Method
System.Void Canada_Simulator.Program::Main()
Main IL Instruction Count
25
Main IL
call System.Void Canada_Simulator.Program::‌‮‎‮‎‌‫‮‏‪‮‫‌​‭‎‬​‎‌‮‬‎‮()
ldc.i4 -351922595
ldc.i4 -239329991
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.3 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0050: newobj System.Void Canada_Simulator.Program::.ctor()
ldc.i4.0 <null>
call System.Void Canada_Simulator.Program::‫‪‬‪‮​‮‬‮‮‬‮‎‮‪‫‬‎‍‍‮(System.Boolean)
newobj System.Void Star_generator.Form1::.ctor()
call System.Void Canada_Simulator.Program::​‫‭‎‭‎‏‮‫​‏‬‏‏‬‫‬‫‍‭‎‏‮‮(System.Windows.Forms.Form)
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::Menu()
ldloc.0 <null>
ldc.i4 1533047261
mul <null>
ldc.i4 -1141648139
xor <null>
br.s IL_000A: ldc.i4 -239329991
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::FailSafe()
ret <null>
Module Name
xanm.exe
Full Name
xanm.exe
EntryPoint
System.Void Canada_Simulator.Program::Main()
Scope Name
xanm.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xanm
Assembly Version
3.9.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
254
Main Method
System.Void Canada_Simulator.Program::Main()
Main IL Instruction Count
25
Main IL
call System.Void Canada_Simulator.Program::‌‮‎‮‎‌‫‮‏‪‮‫‌​‭‎‬​‎‌‮‬‎‮()
ldc.i4 -351922595
ldc.i4 -239329991
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.3 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0050: newobj System.Void Canada_Simulator.Program::.ctor()
ldc.i4.0 <null>
call System.Void Canada_Simulator.Program::‫‪‬‪‮​‮‬‮‮‬‮‎‮‪‫‬‎‍‍‮(System.Boolean)
newobj System.Void Star_generator.Form1::.ctor()
call System.Void Canada_Simulator.Program::​‫‭‎‭‎‏‮‫​‏‬‏‏‬‫‬‫‍‭‎‏‮‮(System.Windows.Forms.Form)
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::Menu()
ldloc.0 <null>
ldc.i4 1533047261
mul <null>
ldc.i4 -1141648139
xor <null>
br.s IL_000A: ldc.i4 -239329991
newobj System.Void Canada_Simulator.Program::.ctor()
call System.Void Canada_Simulator.Program::FailSafe()
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Star_generator.Form1.resources
$this.Icon
[NBF]root.IconData
Moon
[NBF]root.Data
Star_generator.Properties.Resources.resources
KnJi
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙