Suspicious
Suspect

ee965815c95155b742ea36dc868dd6a3

PE Executable
MD5: ee965815c95155b742ea36dc868dd6a3
Size: 745.48 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 ee965815c95155b742ea36dc868dd6a3
Sha1 ce184dd29dca1f40aa907cd9d2b0de32286755a0
Sha256 ef2ef9c4bbc252a65d09f98c7dfe0c89a004bf4df3ccc3dcf65230cfcadf580f
Sha384 e491b2de2c0da4322a5ff19f015f30a9ce87268b1f53fd7e7b877231ddbe6ea235c0556b354b20ea4112186d610efd18
Sha512 aff8d8db2588b0e13149c85c49525e5cee3a1ab6349d8699baeeddd999e29788c48c907c479ec14fd7af0bf5d5448cbae11f132268fbdae5daab742ef5460a0e
SSDeep 12288:oSp9eRPAuSSJQ67EKO+qtH2EMl3AdfcfLyGuJrZGgqzfAR+Ai1kuBtkWyZVmeBkR:19+VSWQ67xaNPEmkfuGuJFqzfA8+e
TLSH 67F4E19C7654B18EC553DA728AA4ED34A6213CBB530BC20394E75DAFB90C6E7CE141F2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Ahorcado.FormMenuPrincipal.resources
Ahorcado.Properties.Resources.resources
R
[NBF]root.Data
[NBF]root.Data-preview.png
Task1
[NBF]root.Data
UtsSRG
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xB2A00 size 13832 bytes
Module Name
sDDUjE.exe
Full Name
sDDUjE.exe
EntryPoint
System.Void Ahorcado.Program::Main()
Scope Name
sDDUjE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sDDUjE
Assembly Version
1.1.1.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
200
Main Method
System.Void Ahorcado.Program::Main()
Main IL Instruction Count
25
Main IL
nop <null>
call System.Void Ahorcado.Program::‬​‍‬‫‎‌‪‭‪‍‍‎‭‌​‫‌‫‫‏​‮‮()
nop <null>
ldc.i4.0 <null>
call System.Void Ahorcado.Program::‭‮‌‫‭‍​‏‮‎‪‎‫‏‏‫‭‬‪‪‎‫‮(System.Boolean)
nop <null>
ldc.i4 1977019574
ldc.i4 1964921718
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.3 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0049: nop
newobj System.Void Ahorcado.FormMenuPrincipal::.ctor()
call System.Void Ahorcado.Program::‍‮‫‮‎‪‎‪​​‪‫‎‍‮‫‬‌‎‍‭‪‎‬‮‬‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 1050044658
mul <null>
ldc.i4 933285148
xor <null>
br.s IL_0013: ldc.i4 1964921718
nop <null>
ret <null>
Module Name
sDDUjE.exe
Full Name
sDDUjE.exe
EntryPoint
System.Void Ahorcado.Program::Main()
Scope Name
sDDUjE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
sDDUjE
Assembly Version
1.1.1.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
200
Main Method
System.Void Ahorcado.Program::Main()
Main IL Instruction Count
25
Main IL
nop <null>
call System.Void Ahorcado.Program::‬​‍‬‫‎‌‪‭‪‍‍‎‭‌​‫‌‫‫‏​‮‮()
nop <null>
ldc.i4.0 <null>
call System.Void Ahorcado.Program::‭‮‌‫‭‍​‏‮‎‪‎‫‏‏‫‭‬‪‪‎‫‮(System.Boolean)
nop <null>
ldc.i4 1977019574
ldc.i4 1964921718
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.3 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0049: nop
newobj System.Void Ahorcado.FormMenuPrincipal::.ctor()
call System.Void Ahorcado.Program::‍‮‫‮‎‪‎‪​​‪‫‎‍‮‫‬‌‎‍‭‪‎‬‮‬‮(System.Windows.Forms.Form)
ldloc.0 <null>
ldc.i4 1050044658
mul <null>
ldc.i4 933285148
xor <null>
br.s IL_0013: ldc.i4 1964921718
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Ahorcado.FormMenuPrincipal.resources
Ahorcado.Properties.Resources.resources
R
[NBF]root.Data
[NBF]root.Data-preview.png
Task1
[NBF]root.Data
UtsSRG
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙