Suspicious
Suspect

05fe479368179099a9ee67e9c0dfa085

PE Executable
MD5: 05fe479368179099a9ee67e9c0dfa085
Size: 17.06 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 05fe479368179099a9ee67e9c0dfa085
Sha1 185b64b062fb6e56b8230814b857d108e41e309b
Sha256 2af66155c2e3e53b7068e820f6387d18fdfa4276faa18b1d0337410d096336e2
Sha384 f20732e1c5dbf8f4dad008ab961153dc901bee8412462f430d01ffe9ea4e16d0ce8df647564f79c6b6d4ed7cffb90d04
Sha512 2de467672e44cb50a334d542382e773a5e2b2b7f421bc4ff96bcb4b0e6f994201121530633116ce820b3995e403d3d2ff0ffc88ad1cb5e0995ee596f2079f34c
SSDeep 196608:TP4FMIZETSRjPePdrQJF0BAnPh4OKJsTBq3hNA0nZSfBZYZee8p8rJup6EjS8XTI:bQETSRvJFDxdBohNdn8Eee8gaTde
TLSH 4B07338393A089FBD3818474C099E7656AB2B53E9F6605063EE465CD3F0BB94187EF31
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Binded.Resources
Overlay_7956cc44.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.hd-
.NBE
.7dN
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
binded.exe
Full Name
binded.exe
EntryPoint
System.Void Bind.Binder::Main()
Scope Name
binded.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
binded
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
9
Main Method
System.Void Bind.Binder::Main()
Main IL Instruction Count
45
Main IL
ldstr TEMP
ldc.i4.1 <null>
call System.String System.Environment::GetEnvironmentVariable(System.String,System.EnvironmentVariableTarget)
ldstr \
call System.String System.String::Concat(System.String,System.String)
stloc.0 <null>
ldstr Binded
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
newobj System.Void System.Resources.ResourceManager::.ctor(System.String,System.Reflection.Assembly)
stloc.1 <null>
ldloc.0 <null>
ldstr XExector.exe
call System.String System.String::Concat(System.String,System.String)
ldloc.1 <null>
ldstr XExector.exeResource
callvirt System.Object System.Resources.ResourceManager::GetObject(System.String)
castclass System.Byte[]
call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[])
ldloc.0 <null>
ldstr XExector.exe
call System.String System.String::Concat(System.String,System.String)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String)
pop <null>
ldloc.0 <null>
ldstr plaguecheat.exe
call System.String System.String::Concat(System.String,System.String)
ldloc.1 <null>
ldstr plaguecheat.exeResource
callvirt System.Object System.Resources.ResourceManager::GetObject(System.String)
castclass System.Byte[]
call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[])
ldloc.0 <null>
ldstr plaguecheat.exe
call System.String System.String::Concat(System.String,System.String)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String)
pop <null>
leave.s IL_009E: ret
stloc.2 <null>
ldloc.2 <null>
callvirt System.String System.Exception::get_Message()
call System.Void System.Console::WriteLine(System.String)
call System.Int32 System.Console::Read()
pop <null>
leave.s IL_009E: ret
ret <null>
Module Name
binded.exe
Full Name
binded.exe
EntryPoint
System.Void Bind.Binder::Main()
Scope Name
binded.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
binded
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
9
Main Method
System.Void Bind.Binder::Main()
Main IL Instruction Count
45
Main IL
ldstr TEMP
ldc.i4.1 <null>
call System.String System.Environment::GetEnvironmentVariable(System.String,System.EnvironmentVariableTarget)
ldstr \
call System.String System.String::Concat(System.String,System.String)
stloc.0 <null>
ldstr Binded
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
newobj System.Void System.Resources.ResourceManager::.ctor(System.String,System.Reflection.Assembly)
stloc.1 <null>
ldloc.0 <null>
ldstr XExector.exe
call System.String System.String::Concat(System.String,System.String)
ldloc.1 <null>
ldstr XExector.exeResource
callvirt System.Object System.Resources.ResourceManager::GetObject(System.String)
castclass System.Byte[]
call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[])
ldloc.0 <null>
ldstr XExector.exe
call System.String System.String::Concat(System.String,System.String)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String)
pop <null>
ldloc.0 <null>
ldstr plaguecheat.exe
call System.String System.String::Concat(System.String,System.String)
ldloc.1 <null>
ldstr plaguecheat.exeResource
callvirt System.Object System.Resources.ResourceManager::GetObject(System.String)
castclass System.Byte[]
call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[])
ldloc.0 <null>
ldstr plaguecheat.exe
call System.String System.String::Concat(System.String,System.String)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String)
pop <null>
leave.s IL_009E: ret
stloc.2 <null>
ldloc.2 <null>
callvirt System.String System.Exception::get_Message()
call System.Void System.Console::WriteLine(System.String)
call System.Int32 System.Console::Read()
pop <null>
leave.s IL_009E: ret
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Binded.Resources
Overlay_7956cc44.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.hd-
.NBE
.7dN
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙