Suspicious
Suspect

0c4c8e2c349f19bb3251e4384614b5f4

PE Executable
MD5: 0c4c8e2c349f19bb3251e4384614b5f4
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0c4c8e2c349f19bb3251e4384614b5f4
Sha1 d618a118469de223656efe0e8dac6ff3f5c930e7
Sha256 bb5cec76a0993cc61f45315e6aea174591fda5df39351b38c1b0552643f73096
Sha384 85f4b8b76b9149e876a6b6e289b29eb72cd99b3917f21713bdb7e679dd0d7a2f6c71f63ebd09e093588fdf836695024e
Sha512 434d2039c729bb857d65e62e4649fed2f53bcf01dd21aa3643f3718272702cd217790efc0346c7a55cf28b8d2a34488b464a72862ad7ee048124aca1ef66edfa
SSDeep 49152:Wvkt62XlaSFNWPjljiFa2RoUYIFe0O1JvzoGdglTHHB72eh2NT:Wv462XlaSFNWPjljiFXRoUYIFe0m
TLSH 06E54A1437F85F23E1BBE273D5B0041667F1E82AB363FB5B6181677A1C93B505801AAB
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Module Name
Client
Full Name
Client
EntryPoint
System.Void 畁罄鰟䦟琷妇ⁱᢒ梘歶Ꮣ�ᙣ쉑媏ⷁ䟫::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Info
PE Detect: PeReader OK (file layout)
Total Strings
11123
Main Method
System.Void 畁罄鰟䦟琷妇ⁱᢒ梘歶Ꮣ�ᙣ쉑媏ⷁ䟫::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 畁罄鰟䦟琷妇ⁱᢒ梘歶Ꮣ�ᙣ쉑媏ⷁ䟫::띚悉ᣰ뀔샰珺㵤㬼硌溏敎迩쨁䷹⨵瘣(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 畁罄鰟䦟琷妇ⁱᢒ梘歶Ꮣ�ᙣ쉑媏ⷁ䟫::᡻봸傥᯹ࡣ䝷鄀텑縓�ᶘ꒲㑾磍⎯춍䯗᏾੹(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 졇⳪첽﹭靃̒鷀촁웴씿睧組㏘굅栿�괄橤ミ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 畁罄鰟䦟琷妇ⁱᢒ梘歶Ꮣ�ᙣ쉑媏ⷁ䟫::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void 畁罄鰟䦟琷妇ⁱᢒ梘歶Ꮣ�ᙣ쉑媏ⷁ䟫::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 畁罄鰟䦟琷妇ⁱᢒ梘歶Ꮣ�ᙣ쉑媏ⷁ䟫::띚悉ᣰ뀔샰珺㵤㬼硌溏敎迩쨁䷹⨵瘣(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 畁罄鰟䦟琷妇ⁱᢒ梘歶Ꮣ�ᙣ쉑媏ⷁ䟫::᡻봸傥᯹ࡣ䝷鄀텑縓�ᶘ꒲㑾磍⎯춍䯗᏾੹(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 졇⳪첽﹭靃̒鷀촁웴씿睧組㏘굅栿�괄橤ミ::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙