Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 0e909a4f3d5cd6f8a61971924d80fca6
Size: 791.55 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 0e909a4f3d5cd6f8a61971924d80fca6
Sha1 f18b8254d39c47964c3b52aadd9e8973a0fd7bf2
Sha256 566ca7ccb9b63e49ff9bbfe0dc46bfc628d8232f7d45097eeb92518203711b5a
Sha384 5ece02fabf5bc1a1a78deace46404fb78b640e92b879b53aea0219579117fbbcae30327d5449c4435ca856f1ffab6379
Sha512 dc4a2c4d771a1042ee7a05b084c9e501bd2c64c7d80cd88a5668fb9c7151747f87c2e3c89ace10e5b4457a75def3e14443167be291cb86e1dbeca7e5c1f59688
SSDeep 24576:Smt/PnKURVvSPU2lAYajjb/UweAc3ZWM:tt/PnKuvCU2lBagwer3ZW
TLSH 5BF4124DFA76FD21C90E0B36C62309B441A78D56F56BF26B1C8538D35A3B784C0CA697
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
Poeh.exe
Full Name
Poeh.exe
EntryPoint
System.Void DamassaProject.Program::Main()
Scope Name
Poeh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Poeh
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void DamassaProject.Program::Main()
Main IL Instruction Count
27
Main IL
ldsfld System.Int32[] DamassaProject.Properties.Resources::Ⴀ
stloc.2 <null>
ldc.i4.3 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void DamassaProject.fmrSplash::Ⴃ()
ldc.i4 970
ldc.i4 1000
call System.Void DamassaProject.fmrSplash::Ⴜ(System.Int16,System.Int16)
ldc.i4.0 <null>
ldc.i4 374
ldc.i4 291
call System.Void DamassaProject.fmrLogin::Ⴄ(System.Boolean,System.Int16,System.Int16)
ldloc.2 <null>
ldc.i4 240
ldelem.i4 <null>
ldc.i4 60612
sub <null>
stloc.1 <null>
br.s IL_0008: ldloc.1
newobj System.Void DamassaProject.fmrListarUsuario::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void DamassaProject.Program::Main()
pop <null>
ret <null>
Module Name
Poeh.exe
Full Name
Poeh.exe
EntryPoint
System.Void DamassaProject.Program::Main()
Scope Name
Poeh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Poeh
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void DamassaProject.Program::Main()
Main IL Instruction Count
27
Main IL
ldsfld System.Int32[] DamassaProject.Properties.Resources::Ⴀ
stloc.2 <null>
ldc.i4.3 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void DamassaProject.fmrSplash::Ⴃ()
ldc.i4 970
ldc.i4 1000
call System.Void DamassaProject.fmrSplash::Ⴜ(System.Int16,System.Int16)
ldc.i4.0 <null>
ldc.i4 374
ldc.i4 291
call System.Void DamassaProject.fmrLogin::Ⴄ(System.Boolean,System.Int16,System.Int16)
ldloc.2 <null>
ldc.i4 240
ldelem.i4 <null>
ldc.i4 60612
sub <null>
stloc.1 <null>
br.s IL_0008: ldloc.1
newobj System.Void DamassaProject.fmrListarUsuario::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void DamassaProject.Program::Main()
pop <null>
ret <null>
Embedded Resources UNKNWOWN
0huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙