Suspicious
Suspect

0ef492da421b72a19541d1ae856efdff

PE Executable
MD5: 0ef492da421b72a19541d1ae856efdff
Size: 153.09 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 0ef492da421b72a19541d1ae856efdff
Sha1 6b97bf764e3c924ac217209a49a41b8297ccb79d
Sha256 ddb1fae4a772b5eb9db713b5974e5ffcbc5f712a0be8b1081323e91227d64e79
Sha384 f249cb12935618fa47dad87b538c19e9f5ccae51b88b284f4de9aa14dd2d8f14e44fd3367b88c254a8ee95341ecfbc0c
Sha512 b9b79a831ba7ca183933dd6ef00f15ad9e2c801377a49b74730f354ace129d0fcb6d806616d4f780db697f0e839d6aa2b99397f90c2fcc1331c25501c0dd2996
SSDeep 3072:fN6ER87+Qu9v6p2mF5YPl5Qtv8a+RoeXIWnrLCRrKRjoQA8:fTsu9v02mFADa+RDXIUrLC1KRj
TLSH 6FE30257DFD41935CFAACF3C615564429776EE81AC2B6BAB13C5A04B3AA934CE031B20
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
deploy.Properties.Resources.resources
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
deploy.exe
Full Name
deploy.exe
EntryPoint
System.Void deploy.Program::Main(System.String[])
Scope Name
deploy.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
deploy
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
26
Main Method
System.Void deploy.Program::Main(System.String[])
Main IL Instruction Count
69
Main IL
nop <null>
call System.String deploy.Properties.Resources::get_message()
stloc.0 <null>
ldc.i4.0 <null>
newarr System.String
stloc.1 <null>
nop <null>
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
ldc.i4.1 <null>
newarr System.Char
dup <null>
ldc.i4.0 <null>
ldc.i4.s 32
stelem.i2 <null>
callvirt System.String[] System.String::Split(System.Char[])
stloc.1 <null>
nop <null>
leave.s IL_002B: ldloc.0
pop <null>
nop <null>
nop <null>
leave.s IL_002B: ldloc.0
ldloc.0 <null>
call System.Byte[] System.Convert::FromBase64String(System.String)
call System.Byte[] deploy.Program::streaming(System.Byte[])
stloc.2 <null>
ldloc.2 <null>
call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
stloc.3 <null>
ldloc.3 <null>
ldstr balance.restrict
callvirt System.Type System.Reflection.Assembly::GetType(System.String)
stloc.s V_4
ldloc.s V_4
ldstr reputation
ldc.i4.s 56
callvirt System.Reflection.MethodInfo System.Type::GetMethod(System.String,System.Reflection.BindingFlags)
stloc.s V_5
nop <null>
ldloc.s V_5
ldnull <null>
ldc.i4.1 <null>
newarr System.Object
dup <null>
ldc.i4.0 <null>
ldloc.1 <null>
stelem.ref <null>
callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[])
pop <null>
nop <null>
leave.s IL_0090: ret
stloc.s V_6
nop <null>
ldloc.s V_5
ldnull <null>
ldc.i4.1 <null>
newarr System.Object
dup <null>
ldc.i4.0 <null>
ldc.i4.0 <null>
newarr System.String
stelem.ref <null>
callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[])
pop <null>
nop <null>
leave.s IL_0090: ret
ret <null>
Module Name
deploy.exe
Full Name
deploy.exe
EntryPoint
System.Void deploy.Program::Main(System.String[])
Scope Name
deploy.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
deploy
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
26
Main Method
System.Void deploy.Program::Main(System.String[])
Main IL Instruction Count
69
Main IL
nop <null>
call System.String deploy.Properties.Resources::get_message()
stloc.0 <null>
ldc.i4.0 <null>
newarr System.String
stloc.1 <null>
nop <null>
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
ldc.i4.1 <null>
newarr System.Char
dup <null>
ldc.i4.0 <null>
ldc.i4.s 32
stelem.i2 <null>
callvirt System.String[] System.String::Split(System.Char[])
stloc.1 <null>
nop <null>
leave.s IL_002B: ldloc.0
pop <null>
nop <null>
nop <null>
leave.s IL_002B: ldloc.0
ldloc.0 <null>
call System.Byte[] System.Convert::FromBase64String(System.String)
call System.Byte[] deploy.Program::streaming(System.Byte[])
stloc.2 <null>
ldloc.2 <null>
call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
stloc.3 <null>
ldloc.3 <null>
ldstr balance.restrict
callvirt System.Type System.Reflection.Assembly::GetType(System.String)
stloc.s V_4
ldloc.s V_4
ldstr reputation
ldc.i4.s 56
callvirt System.Reflection.MethodInfo System.Type::GetMethod(System.String,System.Reflection.BindingFlags)
stloc.s V_5
nop <null>
ldloc.s V_5
ldnull <null>
ldc.i4.1 <null>
newarr System.Object
dup <null>
ldc.i4.0 <null>
ldloc.1 <null>
stelem.ref <null>
callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[])
pop <null>
nop <null>
leave.s IL_0090: ret
stloc.s V_6
nop <null>
ldloc.s V_5
ldnull <null>
ldc.i4.1 <null>
newarr System.Object
dup <null>
ldc.i4.0 <null>
ldc.i4.0 <null>
newarr System.String
stelem.ref <null>
callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[])
pop <null>
nop <null>
leave.s IL_0090: ret
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
deploy.Properties.Resources.resources
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙