Suspicious
Suspect

080e33b6579f04b3fcac2718e4d77c5a

PE Executable
|
MD5: 080e33b6579f04b3fcac2718e4d77c5a
|
Size: 956.93 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
080e33b6579f04b3fcac2718e4d77c5a
Sha1
f5ec3568a805962913fc8d74ff00bfe8b7cc1246
Sha256
9c3ad2c9b081bf1aa51d44a440c25fd6884f08dd8a965625de8d0312173c51f9
Sha384
724e35296145dfbae52744f46e2170768a1b16c469a374553dbf985526456d694979d53dd21fb320304b3ef2b03e225b
Sha512
c69e385f732b58fc27b9838896d0d36331727779a40620989ee5f87c9119986a3a94904952e98c0247fdabbf9003f99987ee9ca723f0f54cca8851253148285e
SSDeep
12288:bnUAK2q5b9XjilseLYBhXrMeT7e7yIw9LNg9ZunLPKstytYyn37lrzdlqLPHTVH8:jU/2ges9re7lw9Wr8SB7lXvqzRHKt
TLSH
3115122A5AC64817C66C8A77C07151285370DCABA143E3EE5DC867F4BDF3B6ACE53092

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Yn4p9.Resources.resources
Yn4p9.g.resources
9d65d44995dbfd.Resources.resources
7a0efea60
[NBF]root.Data
7a0efea61
[NBF]root.Data
7a0efea610
[NBF]root.Data
7a0efea611
[NBF]root.Data
7a0efea612
[NBF]root.Data
7a0efea613
[NBF]root.Data
7a0efea614
[NBF]root.Data
7a0efea615
[NBF]root.Data
7a0efea62
[NBF]root.Data
7a0efea63
[NBF]root.Data
7a0efea64
[NBF]root.Data
7a0efea65
[NBF]root.Data
7a0efea66
[NBF]root.Data
7a0efea67
[NBF]root.Data
7a0efea68
[NBF]root.Data
7a0efea69
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Yn4p9

Full Name

Yn4p9

EntryPoint

System.Void Lm1t6.Px89Z::w9KLs()

Scope Name

Yn4p9

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Yn4p9

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

0

Main Method

System.Void Lm1t6.Px89Z::w9KLs()

Main IL Instruction Count

116

Main IL

ldc.i4.2 <null> stloc.s V_9 ldloc.s V_9 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.1 <null> stloc.0 <null> ldc.i4.5 <null> stloc.s V_9 br.s IL_0003: ldloc.s V_9 ldloc.0 <null> ldc.i4.s 24 cgt <null> ldc.i4.0 <null> ceq <null> stloc.s V_4 ldloc.s V_4 brfalse.s IL_005C: ldc.i4.s 13 ldc.i4.1 <null> stloc.s V_9 br.s IL_0003: ldloc.s V_9 ldc.i4.s 13 br.s IL_0058: stloc.s V_9 ldc.i4.s 24 stloc.0 <null> ldc.i4.8 <null> stloc.s V_9 br.s IL_0003: ldloc.s V_9 ldloc.0 <null> ldc.i4.s 24 clt <null> stloc.s V_5 ldloc.s V_5 brfalse.s IL_0079: ldc.i4.0 ldc.i4.s 11 stloc.s V_9 br.s IL_0003: ldloc.s V_9 ldc.i4.0 <null> br.s IL_0075: stloc.s V_9 ldc.i4.s 24 stloc.0 <null> ldc.i4.0 <null> stloc.s V_9 br IL_0003: ldloc.s V_9 ldc.i4.8 <null> stloc.s V_9 br IL_0003: ldloc.s V_9 ldloc.0 <null> ldc.i4.s 24 rem <null> ldc.i4.0 <null> ceq <null> stloc.s V_6 ldloc.s V_6 brfalse.s IL_00A4: ldc.i4.5 ldc.i4.6 <null> stloc.s V_9 br IL_0003: ldloc.s V_9 ldc.i4.5 <null> br.s IL_009D: stloc.s V_9 ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newarr System.Object stloc.1 <null> ldc.i4.7 <null> ldc.i4 132364120 ldnull <null> ldc.i4.0 <null> call System.String w9E3Ma.z6Z1Cj::q4NCs2(System.Int32,System.Int32,w9E3Ma.z6Z1Cj,System.Int32) stloc.2 <null> ldc.i4.3 <null> stloc.s V_9 br IL_0003: ldloc.s V_9 ldloc.2 <null> isinst System.String call System.Byte[] i4A.Ya0::n9HEi1(System.String) stloc.3 <null> ldloc.1 <null> isinst System.Object[] ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldloc.3 <null> castclass System.Byte[] call System.Byte[] m9YD.Xe20::Tx38L(System.Byte[]) stelem.ref <null> ldc.i4.s 10 stloc.s V_9 br IL_0003: ldloc.s V_9 ldloc.1 <null> isinst System.Object[] ldloc.0 <null> call System.Void Lm1t6.Px89Z::f9EBb(System.Object[],System.Int32) leave.s IL_0123: ldc.i4.4 dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_7 ldloc.s V_7 isinst System.Exception callvirt System.String System.Exception::get_Message() ldc.i4.0 <null> ldnull <null> call Microsoft.VisualBasic.MsgBoxResult Microsoft.VisualBasic.Interaction::MsgBox(System.Object,Microsoft.VisualBasic.MsgBoxStyle,System.Object) pop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0123: ldc.i4.4 ldc.i4.4 <null> stloc.s V_11 ldloc.s V_11 switch dnlib.DotNet.Emit.Instruction[] ret <null> ldtoken System.Void Lm1t6.Px89Z::w9KLs() pop <null> ret <null>

Module Name

Yn4p9

Full Name

Yn4p9

EntryPoint

System.Void Lm1t6.Px89Z::w9KLs()

Scope Name

Yn4p9

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Yn4p9

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

0

Main Method

System.Void Lm1t6.Px89Z::w9KLs()

Main IL Instruction Count

116

Main IL

ldc.i4.2 <null> stloc.s V_9 ldloc.s V_9 switch dnlib.DotNet.Emit.Instruction[] ldc.i4.1 <null> stloc.0 <null> ldc.i4.5 <null> stloc.s V_9 br.s IL_0003: ldloc.s V_9 ldloc.0 <null> ldc.i4.s 24 cgt <null> ldc.i4.0 <null> ceq <null> stloc.s V_4 ldloc.s V_4 brfalse.s IL_005C: ldc.i4.s 13 ldc.i4.1 <null> stloc.s V_9 br.s IL_0003: ldloc.s V_9 ldc.i4.s 13 br.s IL_0058: stloc.s V_9 ldc.i4.s 24 stloc.0 <null> ldc.i4.8 <null> stloc.s V_9 br.s IL_0003: ldloc.s V_9 ldloc.0 <null> ldc.i4.s 24 clt <null> stloc.s V_5 ldloc.s V_5 brfalse.s IL_0079: ldc.i4.0 ldc.i4.s 11 stloc.s V_9 br.s IL_0003: ldloc.s V_9 ldc.i4.0 <null> br.s IL_0075: stloc.s V_9 ldc.i4.s 24 stloc.0 <null> ldc.i4.0 <null> stloc.s V_9 br IL_0003: ldloc.s V_9 ldc.i4.8 <null> stloc.s V_9 br IL_0003: ldloc.s V_9 ldloc.0 <null> ldc.i4.s 24 rem <null> ldc.i4.0 <null> ceq <null> stloc.s V_6 ldloc.s V_6 brfalse.s IL_00A4: ldc.i4.5 ldc.i4.6 <null> stloc.s V_9 br IL_0003: ldloc.s V_9 ldc.i4.5 <null> br.s IL_009D: stloc.s V_9 ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newarr System.Object stloc.1 <null> ldc.i4.7 <null> ldc.i4 132364120 ldnull <null> ldc.i4.0 <null> call System.String w9E3Ma.z6Z1Cj::q4NCs2(System.Int32,System.Int32,w9E3Ma.z6Z1Cj,System.Int32) stloc.2 <null> ldc.i4.3 <null> stloc.s V_9 br IL_0003: ldloc.s V_9 ldloc.2 <null> isinst System.String call System.Byte[] i4A.Ya0::n9HEi1(System.String) stloc.3 <null> ldloc.1 <null> isinst System.Object[] ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldloc.3 <null> castclass System.Byte[] call System.Byte[] m9YD.Xe20::Tx38L(System.Byte[]) stelem.ref <null> ldc.i4.s 10 stloc.s V_9 br IL_0003: ldloc.s V_9 ldloc.1 <null> isinst System.Object[] ldloc.0 <null> call System.Void Lm1t6.Px89Z::f9EBb(System.Object[],System.Int32) leave.s IL_0123: ldc.i4.4 dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_7 ldloc.s V_7 isinst System.Exception callvirt System.String System.Exception::get_Message() ldc.i4.0 <null> ldnull <null> call Microsoft.VisualBasic.MsgBoxResult Microsoft.VisualBasic.Interaction::MsgBox(System.Object,Microsoft.VisualBasic.MsgBoxStyle,System.Object) pop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0123: ldc.i4.4 ldc.i4.4 <null> stloc.s V_11 ldloc.s V_11 switch dnlib.DotNet.Emit.Instruction[] ret <null> ldtoken System.Void Lm1t6.Px89Z::w9KLs() pop <null> ret <null>

080e33b6579f04b3fcac2718e4d77c5a (956.93 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Yn4p9.Resources.resources
Yn4p9.g.resources
9d65d44995dbfd.Resources.resources
7a0efea60
[NBF]root.Data
7a0efea61
[NBF]root.Data
7a0efea610
[NBF]root.Data
7a0efea611
[NBF]root.Data
7a0efea612
[NBF]root.Data
7a0efea613
[NBF]root.Data
7a0efea614
[NBF]root.Data
7a0efea615
[NBF]root.Data
7a0efea62
[NBF]root.Data
7a0efea63
[NBF]root.Data
7a0efea64
[NBF]root.Data
7a0efea65
[NBF]root.Data
7a0efea66
[NBF]root.Data
7a0efea67
[NBF]root.Data
7a0efea68
[NBF]root.Data
7a0efea69
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙