Suspicious
Suspect

PE Executable
MD5: f0cdee3aac59364064504afaa97a138b
Size: 539.65 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 f0cdee3aac59364064504afaa97a138b
Sha1 61eb41bbbd504e262cb37a90e1d29c7ee61159f3
Sha256 144db9817dfd0a6e61cf7dd18c34c862be3e98fda4e7bf18f230149703575e3b
Sha384 0d3ce9b13953473a6383117f004adef0dc626125a91b3e633e7b093796b06532f14683880db557d3fb9dd07e3a33386d
Sha512 92ce38a6b334513ed8d1a4c62b561ec8c4774fa9db69c757d201b1041ff1f8845aa6dc8b5ccd8a8d04a426ba38a79884f6c9932801340f0d61f5762574930a6c
SSDeep 12288:QQzh5+hGmhK7fOqpRqSuSy7tsZeKV2h4:QQzh0hGmh4JuSypKvG
TLSH 41B4F05512B6DE06D5A163B308B0F6741F7E2DA5A822F24A5BEA3EDB7D72F100D04393
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NimGame.MainMenuForm.resources
NimGame.Properties.Resources.resources
PIA
[NBF]root.Data
ejjm
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: OsWo.pdb
Module Name
OsWo.exe
Full Name
OsWo.exe
EntryPoint
System.Void NimGame.Program::Main()
Scope Name
OsWo.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
OsWo
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
231
Main Method
System.Void NimGame.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NimGame.MainMenuForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NimGame.MainMenuForm.resources
NimGame.Properties.Resources.resources
PIA
[NBF]root.Data
ejjm
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙