Suspicious
Suspect

PE Executable
MD5: 10fad73bcab03506e26422b9f2069eef
Size: 1.09 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 10fad73bcab03506e26422b9f2069eef
Sha1 17150765f31100cf660d14cc8376f854d1fee379
Sha256 6a58063fd4bfe4c9fd2bb7b17216fe3353a358a404d8b162d8b6f2a9bfc7b625
Sha384 a4489698fc6398c9e8f1faf0c6b7acdbbd9d98ed367a2977d9b72a5b781b0fa6a2254c9410ad2a00976854ac4c989215
Sha512 1e56e9bbc0356ea97c75f8650fa1795c6aca7d8d726c41c840f68c8f8bda30c8db9f8eaca5846a108e579f80976b62742992d92a1b283e7e193d8cdba7d2ae3a
SSDeep 24576:Bnzx2PCC7MIrKTTIOJofW3cLdD9ovATQGj52xS6f4qKkev3:BE6ro0Ofsc+IEGj52xFfMk
TLSH 923533BD4F87654EE0D6A97F862B91862B91C3B680FD77FE778E442305029314E63346
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Pebvyshl.Properties.Resources.resources
Tvfbspc
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Zlsrrrmdb
Full Name
Zlsrrrmdb
EntryPoint
System.Void Pebvyshl.Ohnxykfnv::Main()
Scope Name
Zlsrrrmdb
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Zlsrrrmdb
Assembly Version
1.0.4418.1092
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
16
Main Method
System.Void Pebvyshl.Ohnxykfnv::Main()
Main IL Instruction Count
42
Main IL
newobj System.Void Pebvyshl.Vhdnssqaj::.ctor()
stloc.0 <null>
newobj System.Void Pebvyshl.Dqkfdlv::.ctor()
stloc.1 <null>
newobj System.Void Pebvyshl.Vuqfesrb::.ctor()
stloc.2 <null>
newobj System.Void Pebvyshl.Bvbwbrppt::.ctor()
stloc.3 <null>
ldloc.1 <null>
ldloc.2 <null>
ldloc.3 <null>
newobj System.Void Pebvyshl.Xfgvv::.ctor(Pebvyshl.Dqkfdlv,Pebvyshl.Vuqfesrb,Pebvyshl.Bvbwbrppt)
stloc.s V_4
ldloc.0 <null>
ldloc.s V_4
ldftn System.Void Pebvyshl.Xfgvv::Pfmadyrtz(System.Object,Pebvyshl.Hkhihpyohyo)
newobj System.Void System.EventHandler`1<Pebvyshl.Hkhihpyohyo>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Pebvyshl.Vhdnssqaj::add_DownloadCompleted(System.EventHandler`1<Pebvyshl.Hkhihpyohyo>)
ldloc.1 <null>
ldloc.s V_4
ldftn System.Void Pebvyshl.Xfgvv::Rhzhxqyegs(System.Object,Pebvyshl.Puibu)
newobj System.Void System.EventHandler`1<Pebvyshl.Puibu>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Pebvyshl.Dqkfdlv::add_DecryptionCompleted(System.EventHandler`1<Pebvyshl.Puibu>)
ldloc.2 <null>
ldloc.s V_4
ldftn System.Void Pebvyshl.Xfgvv::Xczlaz(System.Object,Pebvyshl.Hdarhp)
newobj System.Void System.EventHandler`1<Pebvyshl.Hdarhp>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Pebvyshl.Vuqfesrb::add_LoadCompleted(System.EventHandler`1<Pebvyshl.Hdarhp>)
ldloc.3 <null>
ldloc.s V_4
ldftn System.Void Pebvyshl.Xfgvv::Acakdhmdf(System.Object,Pebvyshl.Xtkrkx)
newobj System.Void System.EventHandler`1<Pebvyshl.Xtkrkx>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Pebvyshl.Bvbwbrppt::add_InvocationCompleted(System.EventHandler`1<Pebvyshl.Xtkrkx>)
ldloc.0 <null>
callvirt System.Void Pebvyshl.Vhdnssqaj::Ovrhz()
leave.s IL_0082: ret
ldloc.s V_4
brfalse.s IL_0081: endfinally
ldloc.s V_4
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ret <null>
Module Name
Zlsrrrmdb
Full Name
Zlsrrrmdb
EntryPoint
System.Void Pebvyshl.Ohnxykfnv::Main()
Scope Name
Zlsrrrmdb
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Zlsrrrmdb
Assembly Version
1.0.4418.1092
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
16
Main Method
System.Void Pebvyshl.Ohnxykfnv::Main()
Main IL Instruction Count
42
Main IL
newobj System.Void Pebvyshl.Vhdnssqaj::.ctor()
stloc.0 <null>
newobj System.Void Pebvyshl.Dqkfdlv::.ctor()
stloc.1 <null>
newobj System.Void Pebvyshl.Vuqfesrb::.ctor()
stloc.2 <null>
newobj System.Void Pebvyshl.Bvbwbrppt::.ctor()
stloc.3 <null>
ldloc.1 <null>
ldloc.2 <null>
ldloc.3 <null>
newobj System.Void Pebvyshl.Xfgvv::.ctor(Pebvyshl.Dqkfdlv,Pebvyshl.Vuqfesrb,Pebvyshl.Bvbwbrppt)
stloc.s V_4
ldloc.0 <null>
ldloc.s V_4
ldftn System.Void Pebvyshl.Xfgvv::Pfmadyrtz(System.Object,Pebvyshl.Hkhihpyohyo)
newobj System.Void System.EventHandler`1<Pebvyshl.Hkhihpyohyo>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Pebvyshl.Vhdnssqaj::add_DownloadCompleted(System.EventHandler`1<Pebvyshl.Hkhihpyohyo>)
ldloc.1 <null>
ldloc.s V_4
ldftn System.Void Pebvyshl.Xfgvv::Rhzhxqyegs(System.Object,Pebvyshl.Puibu)
newobj System.Void System.EventHandler`1<Pebvyshl.Puibu>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Pebvyshl.Dqkfdlv::add_DecryptionCompleted(System.EventHandler`1<Pebvyshl.Puibu>)
ldloc.2 <null>
ldloc.s V_4
ldftn System.Void Pebvyshl.Xfgvv::Xczlaz(System.Object,Pebvyshl.Hdarhp)
newobj System.Void System.EventHandler`1<Pebvyshl.Hdarhp>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Pebvyshl.Vuqfesrb::add_LoadCompleted(System.EventHandler`1<Pebvyshl.Hdarhp>)
ldloc.3 <null>
ldloc.s V_4
ldftn System.Void Pebvyshl.Xfgvv::Acakdhmdf(System.Object,Pebvyshl.Xtkrkx)
newobj System.Void System.EventHandler`1<Pebvyshl.Xtkrkx>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Pebvyshl.Bvbwbrppt::add_InvocationCompleted(System.EventHandler`1<Pebvyshl.Xtkrkx>)
ldloc.0 <null>
callvirt System.Void Pebvyshl.Vhdnssqaj::Ovrhz()
leave.s IL_0082: ret
ldloc.s V_4
brfalse.s IL_0081: endfinally
ldloc.s V_4
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Pebvyshl.Properties.Resources.resources
Tvfbspc
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙