Suspicious
Suspect

0e8117413e01170023089c95fd91dc6f

PE Executable
MD5: 0e8117413e01170023089c95fd91dc6f
Size: 1.45 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 0e8117413e01170023089c95fd91dc6f
Sha1 edfe8c5b6e6f5c183274ba3fe584883ab28fc82d
Sha256 db4b6c524cbbdb661779fbc66a2f4c7369df8babc733ef965b279542477b2aca
Sha384 8817d0819c521da18891eb593ea7ba1870fd04abd0a4ee5c5633631b4072688de9aed1510f8addd58e25244bfd56676f
Sha512 65c37224278b41305cbcaf4458ef163ab84a7d7e23ee8ba50279123632d6cf7e6ad77d4508009f4f03a2b6dd32aadb1d5e4469a002f9817e4901fb44a59f25d2
SSDeep 24576:NLfpCuNZ1otmVtFTiMkWTZ38JhglcmIZjQnUMKyHdtqD9+0iC4VioMdcD:NzJTFV6W12XDjQbKEo5iC4V5D
TLSH 6B6533AC67E61B87C2758EB0944253541386A3FAB804FFAB7DC50525C75B38C2541BBF
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Overlay_02e34238.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MXwb
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_02e34238.bin (3666 bytes)
Module Name
Vwvrwhpbsfs.exe
Full Name
Vwvrwhpbsfs.exe
EntryPoint
System.Void Qnomny.Flwbomf::Main()
Scope Name
Vwvrwhpbsfs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Vwvrwhpbsfs
Assembly Version
1.0.6434.11804
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
11
Main Method
System.Void Qnomny.Flwbomf::Main()
Main IL Instruction Count
14
Main IL
newobj System.Void d::.ctor()
ldc.i4 21125
call System.String f::a(System.Int32)
ldc.i4 21222
call System.String f::a(System.Int32)
ldc.i4 21201
call System.String f::a(System.Int32)
ldc.i4 21035
call System.String f::a(System.Int32)
callvirt System.Void d::a(System.String,System.String,System.String,System.String)
leave.s IL_0037: ret
pop <null>
leave.s IL_0037: ret
ret <null>
Module Name
Vwvrwhpbsfs.exe
Full Name
Vwvrwhpbsfs.exe
EntryPoint
System.Void Qnomny.Flwbomf::Main()
Scope Name
Vwvrwhpbsfs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Vwvrwhpbsfs
Assembly Version
1.0.6434.11804
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
11
Main Method
System.Void Qnomny.Flwbomf::Main()
Main IL Instruction Count
14
Main IL
newobj System.Void d::.ctor()
ldc.i4 21125
call System.String f::a(System.Int32)
ldc.i4 21222
call System.String f::a(System.Int32)
ldc.i4 21201
call System.String f::a(System.Int32)
ldc.i4 21035
call System.String f::a(System.Int32)
callvirt System.Void d::a(System.String,System.String,System.String,System.String)
leave.s IL_0037: ret
pop <null>
leave.s IL_0037: ret
ret <null>
Overlay_02e34238.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
MXwb
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙