Suspicious
Suspect

07aebeb9afa402ba7507ad6e82939031

PE Executable
|
MD5: 07aebeb9afa402ba7507ad6e82939031
|
Size: 1.34 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
07aebeb9afa402ba7507ad6e82939031
Sha1
8bc0a5a38408002154e8599726c03595a29c881a
Sha256
88fc71441cbb84f06e8d10c6aa5763581bb5bf39b8bc395e6bccb6c4aa184e70
Sha384
0859a932bc399a17a0783c73fb69d94a9951a6bee7a9ba0d555ce14790012b366bab6a7732ee1a63d6e89a38a72d6f81
Sha512
804f61aec62de14584079e83c350a1d89159cf08ab05e3aca264e7602b69626721169e474586e271d771edf91b6de58a016aa672b678d45c9e7773f6b0fb19de
SSDeep
24576:T8BsZbxLmonhkVk9vum/e29k7dtUmqtC1KObuJx:0CbgonH9v/ec4fJq
TLSH
4255C00AD7C91A94F0BB8770A6715D248BF0B66BE61DFA9F3F2411ED8A117468803377

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
qi2CfFd4n.g.resources
qi2CfFd4n.Resources.resources
3d06d82d85812c.Resources.resources
2746f0aa0
[NBF]root.Data
2746f0aa1
[NBF]root.Data
2746f0aa10
[NBF]root.Data
2746f0aa11
[NBF]root.Data
2746f0aa12
[NBF]root.Data
2746f0aa13
[NBF]root.Data
2746f0aa14
[NBF]root.Data
2746f0aa15
[NBF]root.Data
2746f0aa16
[NBF]root.Data
2746f0aa17
[NBF]root.Data
2746f0aa18
[NBF]root.Data
2746f0aa19
[NBF]root.Data
2746f0aa2
[NBF]root.Data
2746f0aa20
[NBF]root.Data
2746f0aa21
[NBF]root.Data
2746f0aa22
[NBF]root.Data
2746f0aa23
[NBF]root.Data
2746f0aa24
[NBF]root.Data
2746f0aa25
[NBF]root.Data
2746f0aa26
[NBF]root.Data
2746f0aa27
[NBF]root.Data
2746f0aa28
[NBF]root.Data
2746f0aa29
[NBF]root.Data
2746f0aa3
[NBF]root.Data
2746f0aa30
[NBF]root.Data
2746f0aa31
[NBF]root.Data
2746f0aa32
[NBF]root.Data
2746f0aa33
[NBF]root.Data
2746f0aa34
[NBF]root.Data
2746f0aa35
[NBF]root.Data
2746f0aa36
[NBF]root.Data
2746f0aa37
[NBF]root.Data
2746f0aa38
[NBF]root.Data
2746f0aa4
[NBF]root.Data
2746f0aa5
[NBF]root.Data
2746f0aa6
[NBF]root.Data
2746f0aa7
[NBF]root.Data
2746f0aa8
[NBF]root.Data
2746f0aa9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

qi2CfFd4n

Full Name

qi2CfFd4n

EntryPoint

System.Void qi2CfFd4n.B_w9sy5RcWk60/jTo6y1Dxa.7PgiQ::0TcsFbx58()

Scope Name

qi2CfFd4n

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

qi2CfFd4n

Assembly Version

7.19.9.28

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1290

Main Method

System.Void qi2CfFd4n.B_w9sy5RcWk60/jTo6y1Dxa.7PgiQ::0TcsFbx58()

Main IL Instruction Count

104

Main IL

nop <null> nop <null> newobj System.Void qi2CfFd4n.B_w9sy5RcWk60::.ctor() stloc.0 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.2 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.3 <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_4 ldloc.3 <null> ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0049: ldloc.2 br.s IL_0066: ldloc.s V_4 ldloc.2 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken qi2CfFd4n.B_w9sy5RcWk60 call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass qi2CfFd4n.B_w9sy5RcWk60 stloc.0 <null> ldloc.s V_4 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.1 <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_5 nop <null> nop <null> ldc.i4 214 stloc.s V_6 br.s IL_00A9: ldloc.s V_6 ldloc.s V_6 ldc.i4.3 <null> mul.ovf <null> stloc.s V_6 ldloc.s V_6 ldc.i4.s 24 cgt <null> stloc.s V_8 ldloc.s V_8 brfalse.s IL_00A7: nop ldc.i4.s 24 stloc.s V_6 ldstr resources/s call System.Byte[] qi2CfFd4n.Tx0sx3FpyRr/yc8S6KqmdkR.tFg0n5LpHkg1::2XsekiZ1H(System.String) stloc.s V_7 br.s IL_00B7: ldloc.s V_7 nop <null> nop <null> ldloc.s V_6 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_9 ldloc.s V_9 brtrue.s IL_0083: ldloc.s V_6 ldloc.s V_7 castclass System.Byte[] call System.Void qi2CfFd4n.aQp6Zd/k_6AqDi37w.Lcx3aM5gk::eGz8e4PzBga2c6(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00DD: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_10 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00DD: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> ret <null>

Module Name

qi2CfFd4n

Full Name

qi2CfFd4n

EntryPoint

System.Void qi2CfFd4n.B_w9sy5RcWk60/jTo6y1Dxa.7PgiQ::0TcsFbx58()

Scope Name

qi2CfFd4n

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

qi2CfFd4n

Assembly Version

7.19.9.28

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1290

Main Method

System.Void qi2CfFd4n.B_w9sy5RcWk60/jTo6y1Dxa.7PgiQ::0TcsFbx58()

Main IL Instruction Count

104

Main IL

nop <null> nop <null> newobj System.Void qi2CfFd4n.B_w9sy5RcWk60::.ctor() stloc.0 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.2 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.3 <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_4 ldloc.3 <null> ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0049: ldloc.2 br.s IL_0066: ldloc.s V_4 ldloc.2 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken qi2CfFd4n.B_w9sy5RcWk60 call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass qi2CfFd4n.B_w9sy5RcWk60 stloc.0 <null> ldloc.s V_4 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.1 <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_5 nop <null> nop <null> ldc.i4 214 stloc.s V_6 br.s IL_00A9: ldloc.s V_6 ldloc.s V_6 ldc.i4.3 <null> mul.ovf <null> stloc.s V_6 ldloc.s V_6 ldc.i4.s 24 cgt <null> stloc.s V_8 ldloc.s V_8 brfalse.s IL_00A7: nop ldc.i4.s 24 stloc.s V_6 ldstr resources/s call System.Byte[] qi2CfFd4n.Tx0sx3FpyRr/yc8S6KqmdkR.tFg0n5LpHkg1::2XsekiZ1H(System.String) stloc.s V_7 br.s IL_00B7: ldloc.s V_7 nop <null> nop <null> ldloc.s V_6 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_9 ldloc.s V_9 brtrue.s IL_0083: ldloc.s V_6 ldloc.s V_7 castclass System.Byte[] call System.Void qi2CfFd4n.aQp6Zd/k_6AqDi37w.Lcx3aM5gk::eGz8e4PzBga2c6(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00DD: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_10 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00DD: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> ret <null>

07aebeb9afa402ba7507ad6e82939031 (1.34 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
qi2CfFd4n.g.resources
qi2CfFd4n.Resources.resources
3d06d82d85812c.Resources.resources
2746f0aa0
[NBF]root.Data
2746f0aa1
[NBF]root.Data
2746f0aa10
[NBF]root.Data
2746f0aa11
[NBF]root.Data
2746f0aa12
[NBF]root.Data
2746f0aa13
[NBF]root.Data
2746f0aa14
[NBF]root.Data
2746f0aa15
[NBF]root.Data
2746f0aa16
[NBF]root.Data
2746f0aa17
[NBF]root.Data
2746f0aa18
[NBF]root.Data
2746f0aa19
[NBF]root.Data
2746f0aa2
[NBF]root.Data
2746f0aa20
[NBF]root.Data
2746f0aa21
[NBF]root.Data
2746f0aa22
[NBF]root.Data
2746f0aa23
[NBF]root.Data
2746f0aa24
[NBF]root.Data
2746f0aa25
[NBF]root.Data
2746f0aa26
[NBF]root.Data
2746f0aa27
[NBF]root.Data
2746f0aa28
[NBF]root.Data
2746f0aa29
[NBF]root.Data
2746f0aa3
[NBF]root.Data
2746f0aa30
[NBF]root.Data
2746f0aa31
[NBF]root.Data
2746f0aa32
[NBF]root.Data
2746f0aa33
[NBF]root.Data
2746f0aa34
[NBF]root.Data
2746f0aa35
[NBF]root.Data
2746f0aa36
[NBF]root.Data
2746f0aa37
[NBF]root.Data
2746f0aa38
[NBF]root.Data
2746f0aa4
[NBF]root.Data
2746f0aa5
[NBF]root.Data
2746f0aa6
[NBF]root.Data
2746f0aa7
[NBF]root.Data
2746f0aa8
[NBF]root.Data
2746f0aa9
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙