Malicious
Malicious

0b00ee7bbb50b4cb0e6d77d773dc0401

PE Executable
MD5: 0b00ee7bbb50b4cb0e6d77d773dc0401
Size: 2.92 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 0b00ee7bbb50b4cb0e6d77d773dc0401
Sha1 fc238603745e17814877bb109e723a0f37d8c20e
Sha256 bd6dd0383aadbfe35d3ff072e5cfe720252fe7b269da1c8248a3750040f72d0d
Sha384 6264ac4c20b704ab8b9c1b475f01e307e9de8f834420ba89cc6eb6f9558bd27208c6914eb2bee42851130c5b13d13bf3
Sha512 02664f55a42cbe3c343c7a4839cabe49b3fdef2129ea54a8f7a38797b0f81960463ccfbf11bf1f3a45f334e8d90d7fe74894f1b540452af0e910e197ef56cc93
SSDeep 49152:zoZsprea4tennxACMcV9TeODipVIOUK0h/QUTPKdnn1ZMp9SCr60f/rZVdyueSM2:nprf4Mxj/9TrMI+0hYNdn1ZMpBrXZfK6
TLSH 9FD5D0027F54CA02F519123BD2EF854847B4E85166AAE32B7CBE376D65123A73C0D9CB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
.Net Resources
yOvmRNX5XYp25ZEDD1.4ZGIy6kDVA2wE1xZlf
4DLrRPjEsSbWrL6jRu.aAIrQhuHAUrSRKu8vR
Name Value
Module Name
3cbaChOA4Ea
Full Name
3cbaChOA4Ea
EntryPoint
System.Void aKx0oK0yC64JGT9oGSE.LovPCe0e93YoGdpOgBZ::htWlhpL2xR()
Scope Name
3cbaChOA4Ea
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Lv5BLAiI94g9t3YB61DZ5TtfdcdJvqruMegPgXHZ
Assembly Version
8.5.1.9
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void aKx0oK0yC64JGT9oGSE.LovPCe0e93YoGdpOgBZ::htWlhpL2xR()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void tZGcqhh5bG631Mghvr0.cuHa9dh7i45uxsEOnCT::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object aKx0oK0yC64JGT9oGSE.LovPCe0e93YoGdpOgBZ::TORlffMhUk
callvirt System.Void qEuEPH07kAWHD6wQ72o.WCB5Tc0W8QLxBA7L7hO::FfO2w2UOxR()
nop <null>
ret <null>
Module Name
3cbaChOA4Ea
Full Name
3cbaChOA4Ea
EntryPoint
System.Void aKx0oK0yC64JGT9oGSE.LovPCe0e93YoGdpOgBZ::htWlhpL2xR()
Scope Name
3cbaChOA4Ea
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Lv5BLAiI94g9t3YB61DZ5TtfdcdJvqruMegPgXHZ
Assembly Version
8.5.1.9
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void aKx0oK0yC64JGT9oGSE.LovPCe0e93YoGdpOgBZ::htWlhpL2xR()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void tZGcqhh5bG631Mghvr0.cuHa9dh7i45uxsEOnCT::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object aKx0oK0yC64JGT9oGSE.LovPCe0e93YoGdpOgBZ::TORlffMhUk
callvirt System.Void qEuEPH07kAWHD6wQ72o.WCB5Tc0W8QLxBA7L7hO::FfO2w2UOxR()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
.Net Resources
yOvmRNX5XYp25ZEDD1.4ZGIy6kDVA2wE1xZlf
4DLrRPjEsSbWrL6jRu.aAIrQhuHAUrSRKu8vR
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙