Suspicious
Suspect

PE Executable
MD5: fe3954f2a02d9b05e51ea26bcc70d453
Size: 931.33 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 fe3954f2a02d9b05e51ea26bcc70d453
Sha1 80607b94bdf577e367c7e1a017a57367fe7195fc
Sha256 75a4146af3520c8bb236cfe21ef507eec5f8a082ab20f4dfad55765b6fc04049
Sha384 b13d8dbcaf46377b682a34675e49df89b4e83bb2cd978fa9692885f001b54ac86232516c19b3bebd08bc5aa0ff181ab1
Sha512 59ae7c12471c84a14245dbc5543af0645a64f4e81fcc2194f6591ba981baf1422f0d66daa9939e1c209540c80cf6dada346d7c19c55d063c2995e093f7676169
SSDeep 24576:mSnA9EDH2ZXQH9LODKrXy13h/jTtYRqEnHLY+m5zWaolwF:UyeXe9cME3V+RxrY+izHO
TLSH E61522B90306C503D9E107F25CE5E3B46368AEEFB811C357AED9ACE73869711B941253
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NumberGuess.MainForm.resources
NumberGuess.Properties.Resources.resources
gap
[NBF]root.Data
ixir
[NBF]root.Data
[NBF]root.Data-preview.png
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: XdPj.pdb
Module Name
XdPj.exe
Full Name
XdPj.exe
EntryPoint
System.Void NumberGuess.Program::Main()
Scope Name
XdPj.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XdPj
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
102
Main Method
System.Void NumberGuess.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void NumberGuess.MainForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
NumberGuess.MainForm.resources
NumberGuess.Properties.Resources.resources
gap
[NBF]root.Data
ixir
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙