Malicious
Malicious

PE Executable
MD5: 058bcf40526454c01909ce441f8ed42d
Size: 921.6 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 058bcf40526454c01909ce441f8ed42d
Sha1 ff43aefabbdca3638d5091feed6d636606c85faf
Sha256 9f33efdeabd35154a3c3f6bba7955ffdf840e68f07cfae982e9fb4f04fb36750
Sha384 496e0c99da2eafeb153c4f7e8ad9a80db01030458bc2de2825553fc874a1b9a1a1f1db31957eb9eeb273421b028c257a
Sha512 3cb209082fcae0671d06bcb88cf2d537ad3e005a66fb12a74a9eb26670060a6ef52ccd6b967cec663c7a89eba43c609c5d0d17b20c1b637abf9a1448f952558c
SSDeep 12288:hO15eTr6eyot/wFSJxDYG8NsMozZ1WHC4J73BhX8lfgaTfdlgr6Y2:aeTWey2wgJRYGeMZ18dxhMtFTHg2
TLSH 3D15F6027E44CE12F0192233C2EF454887B4A9516BA6F32B7DBA376E55123A77C0D9DB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
NQ6EaVsjaZIgIl2sXD.f3jd6VDoVkFwsSbHeq
ymJx6pOdf2KFUXcDHL.vwwXC10dwg4K9LCrME
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
LoXNWAdF1HJN10QPMQ5U
Full Name
LoXNWAdF1HJN10QPMQ5U
EntryPoint
System.Void q4mFMf9BqEsH0DOatEc.AFVxic9VOrdFiIg51TB::HWOI00lWxT()
Scope Name
LoXNWAdF1HJN10QPMQ5U
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
0JXINyDhy6jLCbTiNx0ayJdI
Assembly Version
6.0.3.5
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void q4mFMf9BqEsH0DOatEc.AFVxic9VOrdFiIg51TB::HWOI00lWxT()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void h1sxBUTqa4XVyi6uDor.N60Nw3T3L62MG0GhE8N::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object q4mFMf9BqEsH0DOatEc.AFVxic9VOrdFiIg51TB::WPMIlKJtxS
callvirt System.Void irTKrI93ycUnnH9DJFH.LQety59MONho7xUEa1A::kx8UJ53WJR()
nop <null>
ret <null>
Module Name
LoXNWAdF1HJN10QPMQ5U
Full Name
LoXNWAdF1HJN10QPMQ5U
EntryPoint
System.Void q4mFMf9BqEsH0DOatEc.AFVxic9VOrdFiIg51TB::HWOI00lWxT()
Scope Name
LoXNWAdF1HJN10QPMQ5U
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
0JXINyDhy6jLCbTiNx0ayJdI
Assembly Version
6.0.3.5
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void q4mFMf9BqEsH0DOatEc.AFVxic9VOrdFiIg51TB::HWOI00lWxT()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void h1sxBUTqa4XVyi6uDor.N60Nw3T3L62MG0GhE8N::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object q4mFMf9BqEsH0DOatEc.AFVxic9VOrdFiIg51TB::WPMIlKJtxS
callvirt System.Void irTKrI93ycUnnH9DJFH.LQety59MONho7xUEa1A::kx8UJ53WJR()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
NQ6EaVsjaZIgIl2sXD.f3jd6VDoVkFwsSbHeq
ymJx6pOdf2KFUXcDHL.vwwXC10dwg4K9LCrME
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙