Suspicious
Suspect

PE Executable
MD5: fe26dd7022a9addd54c330eb72e34c84
Size: 1.25 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 fe26dd7022a9addd54c330eb72e34c84
Sha1 ad8ae4c5bc67ee1e35e570f76a332f7814efceb6
Sha256 27bdcb028d5a949b002ab6337453221e24c2f3d181c7a804eeb2d5ecda123d9d
Sha384 248add5b6b2b49531de8ef54cdebf97b22e4f0a6a9049a440a0f6508efe8e7067c54a0865efcc9cf73d137f1b52c304d
Sha512 2bb576f947340c02b71090953c8f6014a858a4e7bad1cc4e252f0a004b5b20137a9b5c854498442a5cd8d251002d6c32438803f5289801233f062652709948c4
SSDeep 24576:XyfmI2MoIdpWXrOl15Rzsysl6k+kiy/4WMOy:XymIXoIdsXrA5RzsUk+kHwWMOy
TLSH 48452225262AD70AC85167F81AB1E134077A5D9EF916D31B0FE8BCEFBC79B008E54253
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DiceSimulator.Forms.MainForm.resources
DiceSimulator.Properties.Resources.resources
Hasenfresse_mit_Sonnenbrille
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
Strange_Thinking
[NBF]root.Data
[NBF]root.Data-preview.png
yQOl
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: hWPP.pdb
Module Name
hWPP.exe
Full Name
hWPP.exe
EntryPoint
System.Void DiceSimulator.Program::Main()
Scope Name
hWPP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hWPP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
235
Main Method
System.Void DiceSimulator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DiceSimulator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
hWPP.exe
Full Name
hWPP.exe
EntryPoint
System.Void DiceSimulator.Program::Main()
Scope Name
hWPP.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hWPP
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
235
Main Method
System.Void DiceSimulator.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void DiceSimulator.Forms.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
DiceSimulator.Forms.MainForm.resources
DiceSimulator.Properties.Resources.resources
Hasenfresse_mit_Sonnenbrille
[NBF]root.Data
[NBF]root.Data-preview.png
Sort1
[NBF]root.Data
Strange_Thinking
[NBF]root.Data
[NBF]root.Data-preview.png
yQOl
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙