×
This file seems to be a .NET executable .
Sadly, Manalyzer's analysis techniques were designed for native code, so it's likely that this report won't tell you much.
Sorry!
Architecture
IMAGE_FILE_MACHINE_I386
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date
2045-Jul-14 01:39:13
Debug artifacts
C:\Users\demax\source\repos\FRYBLX\FRYBLX\obj\Debug\FRYBLX.pdb
Comments
CompanyName
FileDescription
FRYBLX
FileVersion
1.0.0.0
InternalName
FRYBLX.exe
LegalCopyright
Copyright © 2026
LegalTrademarks
OriginalFilename
FRYBLX.exe
ProductName
FRYBLX
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Info
Matching compiler(s):
Microsoft Visual C# v7.0 / Basic .NET
Suspicious
Strings found in the binary may indicate undesirable behavior:
Miscellaneous malware strings:
Contains domain names:
http://www.fryblx.dev
http://www.fryblx.dev/game/Join.ashx?token
http://www.fryblx.dev/game/PlaceLauncher.ashx?token
http://www.fryblx.dev/login/negotiate.ashx
https://www.fryblx.dev
https://www.fryblx.dev/install/ccv
https://www.fryblx.dev/install/ccv.php
https://www.fryblx.dev/install/v/
Malicious
VirusTotal score: 4/64 (Scanned on 2026-04-24 05:02:47)
APEX:
Malicious
CrowdStrike:
win/malicious_confidence_60% (W)
MaxSecure:
Trojan.Malware.300983.susgen
VirIT:
Trojan.Win32.MSIL_Heur.A
MD5
438e15cebc5a8675112b4d8c7de06a3e
SHA1
2b12a4e01d6c5a10b7b51131d1a71485d86fce9f
SHA256
4917e97987dc423da543e90daf9fcf151f66a9f310b0ee77c9a49de3a5320d54
SHA3
0bc9526cb62a414c17200914cdbe3b4bc2b631184cf8c5076664d1a1bc445743
SSDeep
768:yW5AU3Zp9p4cqxb1easaSbQlYpFEVxQs+bjbCOVxnaK:p5AU3Ab1e0aAmHCaB
Imports Hash
f34d5f2d4577ed6d9ceec516c1f5a744
e_magic
MZ
e_cblp
0x90
e_cp
0x3
e_crlc
0
e_cparhdr
0x4
e_minalloc
0
e_maxalloc
0xffff
e_ss
0
e_sp
0xb8
e_csum
0
e_ip
0
e_cs
0
e_ovno
0
e_oemid
0
e_oeminfo
0
e_lfanew
0x80
Signature
PE
Machine
IMAGE_FILE_MACHINE_I386
NumberofSections
3
TimeDateStamp
2045-Jul-14 01:39:13
PointerToSymbolTable
0
NumberOfSymbols
0
SizeOfOptionalHeader
0xe0
Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
Magic
PE32
LinkerVersion
48.0
SizeOfCode
0x9200
SizeOfInitializedData
0x600
SizeOfUninitializedData
0
AddressOfEntryPoint
0x0000B1BA (Section: .text)
BaseOfCode
0x2000
BaseOfData
0xc000
ImageBase
0x400000
SectionAlignment
0x2000
FileAlignment
0x200
OperatingSystemVersion
4.0
ImageVersion
0.0
SubsystemVersion
6.0
Win32VersionValue
0
SizeOfImage
0x10000
SizeOfHeaders
0x200
Checksum
0
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve
0x100000
SizeofStackCommit
0x1000
SizeofHeapReserve
0x100000
SizeofHeapCommit
0x1000
LoaderFlags
0
NumberOfRvaAndSizes
16
MD5
b33e35a5ab1d8e3edeb2a0c4f2550ec2
SHA1
84b309fce7cac8cc19bc30551195d759dfc6acb6
SHA256
3476f9df79e6b4dad71516f26acd385b279bc20853f59e17daf898dcbb374175
SHA3
0eddfd985a325d46ad6d16d6915cd56903165a8eaabe2fbea9b71583f9cf29b9
VirtualSize
0x91c0
VirtualAddress
0x2000
SizeOfRawData
0x9200
PointerToRawData
0x200
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy
6.83964
MD5
a4ae6fe95e9e78df11d908b247d3af28
SHA1
c1b630346605227c660a1eebe643f21eb6ad056f
SHA256
8ada5cc28f3df21b6b2cc82caf947308a09201672629552d86297729fa618483
SHA3
8a540830e64cac427d0e1cb5a9ead21c05a76afaf7a1a971bfa916e8c1a6fce2
VirtualSize
0x368
VirtualAddress
0xc000
SizeOfRawData
0x400
PointerToRawData
0x9400
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy
2.76874
MD5
cc9180dc18c54a92c8e315c2e08c2fb5
SHA1
8ff9bf36a4556a24bacbd15b64238de835c665a0
SHA256
64c034fc223a55190260f4f3c47c1b5e6e1a55c39161e66e40190091993d8911
SHA3
0b5aa72c2b5643ebf5535ae75701c3fb7e6ec368d6542d03917c8bc5de435114
VirtualSize
0xc
VirtualAddress
0xe000
SizeOfRawData
0x200
PointerToRawData
0x9800
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy
0.0815394
Type
RT_VERSION
Language
UNKNOWN
Codepage
UNKNOWN
Size
0x30c
TimeDateStamp
1980-Jan-01 00:00:00
Entropy
3.28576
MD5
cb68b73dcf2cc453e9cd8b0bce4f3a36
SHA1
c8b4cefd28fb9bcb495b4bc41fdf5904ab0653ba
SHA256
1ac3aa52c805bd6ff3c15cd66ff85b7b4577ae4a23ed64948721a188ab0f6ce3
SHA3
da280c550143ca5e4c51783284c9c66fee7942da90015bc6fac2284b69307e57
Signature
0xfeef04bd
StructVersion
0x10000
FileVersion
1.0.0.0
ProductVersion
1.0.0.0
FileFlags
(EMPTY)
FileOs
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType
VFT_APP
Language
UNKNOWN
Comments
CompanyName
FileDescription
FRYBLX
FileVersion (#2)
1.0.0.0
InternalName
FRYBLX.exe
LegalCopyright
Copyright © 2026
LegalTrademarks
OriginalFilename
FRYBLX.exe
ProductName
FRYBLX
ProductVersion (#2)
1.0.0.0
Assembly Version
1.0.0.0
Characteristics
0
TimeDateStamp
2103-Dec-22 12:10:35
Version
0.0
SizeofData
87
AddressOfRawData
0xb110
PointerToRawData
0x9310
Referenced File
C:\Users\demax\source\repos\FRYBLX\FRYBLX\obj\Debug\FRYBLX.pdb
Characteristics
0
TimeDateStamp
1970-Jan-01 00:00:00
Version
0.0
SizeofData
0
AddressOfRawData
0
PointerToRawData
0