Suspicious
Suspect

PE Executable
MD5: 0fe900d19ee3853bb96b268c67732ee9
Size: 1.31 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 0fe900d19ee3853bb96b268c67732ee9
Sha1 8611f388c54f487401673e07e9ff7da9d1d06ad0
Sha256 02b818e2058a60b7e826d6187c970f6a3e377c00fcb650a2af867ee8fe10fee1
Sha384 6347358096c303773d9287a395b8f5d7057575cde25651de1ffdffe48fb498b6cef955079e66c15cf72d2ba376ace669
Sha512 3e2c885716a211c9167b1b27752e8a83e9614cb93421f800283e1a8ad96a77015b06255cbd2a57c00e86ddf2167485ca16430a5a4ed51e2908a2765f6b97d776
SSDeep 12288:N42N7TvzcLW8KGZvSxVxCid+GJIPvyyqhxGUsoIcVaZrP3stHNfexKTiYkNV9V0S:N421IMGoxVzWP+20tAYkNVkt01nJVHH
TLSH 215532342EEA502AF173AF7D8AE47596DA5FBAA33707985D00B103C60723A42DDD153E
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
9BnTZmD7gu0Nm1LpGBRzodgC2YxV62WqxJPOHqL9eHa2
Full Name
9BnTZmD7gu0Nm1LpGBRzodgC2YxV62WqxJPOHqL9eHa2
EntryPoint
System.Void 74V.PEs::627()
Scope Name
9BnTZmD7gu0Nm1LpGBRzodgC2YxV62WqxJPOHqL9eHa2
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
29vNqGgSiVffkaBzr
Assembly Version
0.6.4.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1779
Main Method
System.Void 74V.PEs::627()
Main IL Instruction Count
5
Main IL
nop <null>
ldsfld ab2.2J2 74V.PEs::792
callvirt System.Void ab2.2J2::nC6()
nop <null>
ret <null>
Module Name
9BnTZmD7gu0Nm1LpGBRzodgC2YxV62WqxJPOHqL9eHa2
Full Name
9BnTZmD7gu0Nm1LpGBRzodgC2YxV62WqxJPOHqL9eHa2
EntryPoint
System.Void 74V.PEs::627()
Scope Name
9BnTZmD7gu0Nm1LpGBRzodgC2YxV62WqxJPOHqL9eHa2
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
29vNqGgSiVffkaBzr
Assembly Version
0.6.4.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1779
Main Method
System.Void 74V.PEs::627()
Main IL Instruction Count
5
Main IL
nop <null>
ldsfld ab2.2J2 74V.PEs::792
callvirt System.Void ab2.2J2::nC6()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙