Suspicious
Suspect

PE Executable
MD5: 11e7a133c9f1d3d5ded4b361d70bbd76
Size: 90.11 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 11e7a133c9f1d3d5ded4b361d70bbd76
Sha1 5031366518e738d4662d730438fcb47a0d38da62
Sha256 3a845e936d72ed84f1ac69d54eb4ed226068eb0986643feaf24b8532d1014976
Sha384 ebff2f8a164f461642a3a72ed5ad7d50abf1423d64db4b2d308243c5e79d73eefc574ca209939dbd720e96c903265b24
Sha512 9699c94106a22db21f15dbd1fea7ff315791f5224fa8ff61c6da0266ae695e457f529d98e5317ba9e08cbf447b44a00d2c354049fb2a366237194d41ef93b843
SSDeep 1536:BOAcF2tp1+6Ex/XFWeX8KcFyn9QKXw6Wx3lJSwy8WtgedGes:dw2tp1+6ERXFWRD4OKXwGwy8Mkes
TLSH 1F9302B137D41617C69695777EFC3B400F2AC88269E4039D98A56762DCE72072285FF8
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ft00cijgkhr.resources
cmyaesy1ltg
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
morga#n.exe
Full Name
morga#n.exe
EntryPoint
System.Void Loader.Program::Main()
Scope Name
morga#n.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
morga#n
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
5
Main Method
System.Void Loader.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Loader.Nyan::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
morga#n.exe
Full Name
morga#n.exe
EntryPoint
System.Void Loader.Program::Main()
Scope Name
morga#n.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
morga#n
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
5
Main Method
System.Void Loader.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Loader.Nyan::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ft00cijgkhr.resources
cmyaesy1ltg
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙