Suspicious
Suspect

PE Executable
MD5: f1bca3d5bb99015c0fdad3b237c3b266
Size: 796.68 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 f1bca3d5bb99015c0fdad3b237c3b266
Sha1 9820f121bd0e2a5143f5ea0164a184c92c791097
Sha256 246c7a9c17bba40dd3cace1b04a7235eb682ba4ca03d64cfd36067d3f4146222
Sha384 63d1d6a312ecb8df8fc16275e0b890d13a581da47c5d121ac47df6964c6a6711eb8f128146f693f86c4b07489c9f2291
Sha512 026d761d649d9c1c333f259cba4c16352a88c7c679ec086029d92d862375c9151b260231ea18f4eecd3a065f52f26b9204c1587a868458990b681dc64be2c5a1
SSDeep 12288:n0OTMfwUCRBCOA+TVD3OqjwppMi9+2dxyryzJYLXmMTQgYGDNdhxX2lJDCRisixy:Qfw8+L8ppMiDdCXTeyNvVyC4sis
TLSH E90512507669EB02D5616BF45A72F2380BB92E9DF411C30A4EE8BDEBB874F404D60E53
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DiceSimulator.Forms.MainForm.resources
DiceSimulator.Properties.Resources.resources
Hasenfresse_mit_Sonnenbrille
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
Strange_Thinking
[NBF]root.Data
[NBF]root.Data-preview.png
TcRz
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xBF200 size 13832 bytes
Info
PDB Path: xvpe.pdb
Module Name
xvpe.exe
Full Name
xvpe.exe
EntryPoint
System.Void DiceSimulator.Program::Main()
Scope Name
xvpe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xvpe
Assembly Version
3.0.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
235
Main Method
System.Void DiceSimulator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DiceSimulator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
xvpe.exe
Full Name
xvpe.exe
EntryPoint
System.Void DiceSimulator.Program::Main()
Scope Name
xvpe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xvpe
Assembly Version
3.0.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
235
Main Method
System.Void DiceSimulator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DiceSimulator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DiceSimulator.Forms.MainForm.resources
DiceSimulator.Properties.Resources.resources
Hasenfresse_mit_Sonnenbrille
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
Strange_Thinking
[NBF]root.Data
[NBF]root.Data-preview.png
TcRz
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙