Suspicious
Suspect

05fe479368179099a9ee67e9c0dfa085

Share on LinkedIn
Print
PE Executable
MD5: 05fe479368179099a9ee67e9c0dfa085
Size: 17.06 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 05fe479368179099a9ee67e9c0dfa085
Sha1 185b64b062fb6e56b8230814b857d108e41e309b
Sha256 2af66155c2e3e53b7068e820f6387d18fdfa4276faa18b1d0337410d096336e2
Sha384 f20732e1c5dbf8f4dad008ab961153dc901bee8412462f430d01ffe9ea4e16d0ce8df647564f79c6b6d4ed7cffb90d04
Sha512 2de467672e44cb50a334d542382e773a5e2b2b7f421bc4ff96bcb4b0e6f994201121530633116ce820b3995e403d3d2ff0ffc88ad1cb5e0995ee596f2079f34c
SSDeep 196608:TP4FMIZETSRjPePdrQJF0BAnPh4OKJsTBq3hNA0nZSfBZYZee8p8rJup6EjS8XTI:bQETSRvJFDxdBohNdn8Eee8gaTde
TLSH 4B07338393A089FBD3818474C099E7656AB2B53E9F6605063EE465CD3F0BB94187EF31
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Binded.Resources
Overlay_7956cc44.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.hd-
.NBE
.7dN
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
binded.exe
Full Name
binded.exe
EntryPoint
System.Void Bind.Binder::Main()
Scope Name
binded.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
binded
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
9
Main Method
System.Void Bind.Binder::Main()
Main IL Instruction Count
45
Main IL
ldstr TEMP
ldc.i4.1 <null>
call System.String System.Environment::GetEnvironmentVariable(System.String,System.EnvironmentVariableTarget)
ldstr \
call System.String System.String::Concat(System.String,System.String)
stloc.0 <null>
ldstr Binded
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
newobj System.Void System.Resources.ResourceManager::.ctor(System.String,System.Reflection.Assembly)
stloc.1 <null>
ldloc.0 <null>
ldstr XExector.exe
call System.String System.String::Concat(System.String,System.String)
ldloc.1 <null>
ldstr XExector.exeResource
callvirt System.Object System.Resources.ResourceManager::GetObject(System.String)
castclass System.Byte[]
call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[])
ldloc.0 <null>
ldstr XExector.exe
call System.String System.String::Concat(System.String,System.String)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String)
pop <null>
ldloc.0 <null>
ldstr plaguecheat.exe
call System.String System.String::Concat(System.String,System.String)
ldloc.1 <null>
ldstr plaguecheat.exeResource
callvirt System.Object System.Resources.ResourceManager::GetObject(System.String)
castclass System.Byte[]
call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[])
ldloc.0 <null>
ldstr plaguecheat.exe
call System.String System.String::Concat(System.String,System.String)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String)
pop <null>
leave.s IL_009E: ret
stloc.2 <null>
ldloc.2 <null>
callvirt System.String System.Exception::get_Message()
call System.Void System.Console::WriteLine(System.String)
call System.Int32 System.Console::Read()
pop <null>
leave.s IL_009E: ret
ret <null>
Module Name
binded.exe
Full Name
binded.exe
EntryPoint
System.Void Bind.Binder::Main()
Scope Name
binded.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
binded
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
9
Main Method
System.Void Bind.Binder::Main()
Main IL Instruction Count
45
Main IL
ldstr TEMP
ldc.i4.1 <null>
call System.String System.Environment::GetEnvironmentVariable(System.String,System.EnvironmentVariableTarget)
ldstr \
call System.String System.String::Concat(System.String,System.String)
stloc.0 <null>
ldstr Binded
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
newobj System.Void System.Resources.ResourceManager::.ctor(System.String,System.Reflection.Assembly)
stloc.1 <null>
ldloc.0 <null>
ldstr XExector.exe
call System.String System.String::Concat(System.String,System.String)
ldloc.1 <null>
ldstr XExector.exeResource
callvirt System.Object System.Resources.ResourceManager::GetObject(System.String)
castclass System.Byte[]
call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[])
ldloc.0 <null>
ldstr XExector.exe
call System.String System.String::Concat(System.String,System.String)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String)
pop <null>
ldloc.0 <null>
ldstr plaguecheat.exe
call System.String System.String::Concat(System.String,System.String)
ldloc.1 <null>
ldstr plaguecheat.exeResource
callvirt System.Object System.Resources.ResourceManager::GetObject(System.String)
castclass System.Byte[]
call System.Void System.IO.File::WriteAllBytes(System.String,System.Byte[])
ldloc.0 <null>
ldstr plaguecheat.exe
call System.String System.String::Concat(System.String,System.String)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String)
pop <null>
leave.s IL_009E: ret
stloc.2 <null>
ldloc.2 <null>
callvirt System.String System.Exception::get_Message()
call System.Void System.Console::WriteLine(System.String)
call System.Int32 System.Console::Read()
pop <null>
leave.s IL_009E: ret
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙