Suspicious
Suspect

148ee6bc7028182efe69d87047f0a7e9

PE Executable
MD5: 148ee6bc7028182efe69d87047f0a7e9
Size: 434.69 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 148ee6bc7028182efe69d87047f0a7e9
Sha1 27b13cfb5b8dfe3266258bf74c3f14761093311b
Sha256 5155d941fc16d359553f446fc150a95bcf2ca4700e4aaf3ceba975d3b2162d76
Sha384 8cfa9f1207381e6236ff89f0e1eda36d91e469310d408c23afad12ba174617b3afdb64af5133535f1f68d13b74b77089
Sha512 4713d7d010814777d9efa0ecae2ea926e9a133182c356fb8aae7cc8f650d7e363609c867f048d2d057f764bd5fd076593ee985850b41ec6ab49a1c3e154846a4
SSDeep 12288:C/bSajBtt83yT+rZugPSe0Mz+N6mSHCcR:C/bhjBgyIZke0A+QUcR
TLSH D894CFCA63C08D31C9569E3480302E7803379F463E59F246ED68BD7337B7ADA2866597
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
server1.exe
Full Name
server1.exe
EntryPoint
System.Void _85E82F7A309E4CE0_::_8FA4B93866254C5C_()
Scope Name
server1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
server1
Assembly Version
2.1.3.9
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
16
Main Method
System.Void _85E82F7A309E4CE0_::_8FA4B93866254C5C_()
Main IL Instruction Count
65
Main IL
nop <null>
call System.String _85E82F7A309E4CE0_::_893818073A474FDD_()
ldc.i4 -2002263336
br.s IL_000D: call System.String <Module>::_784EDDC5CE584513_<System.String>(System.IntPtr)
call System.String <Module>::_784EDDC5CE584513_<System.String>(System.IntPtr)
call System.String _85E82F7A309E4CE0_::_E1EA628C639949E5_(System.String,System.String)
stsfld System.String _85E82F7A309E4CE0_::_3109EA0E084447BA_
ldsfld System.String _85E82F7A309E4CE0_::_3109EA0E084447BA_
call System.Byte[] _85E82F7A309E4CE0_::_BE93724E6EB74286_(System.String)
stsfld System.Byte[] _85E82F7A309E4CE0_::_A5B892785136489F_
call System.Object _85E82F7A309E4CE0_::_F9D6CF050DA645C4_()
stloc.0 <null>
ldc.i4 239919490
stloc.3 <null>
ldc.i4 2004300895
ldc.i4 707457153
ldc.i4 -137285175
mul <null>
ldloc.3 <null>
ldc.i4 -1977679781
ldc.i4 748530179
mul <null>
add <null>
neg <null>
sub <null>
sub <null>
dup <null>
stloc.2 <null>
ldc.i4.4 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_00D7: ret
ldloc.0 <null>
ldsfld System.Byte[] _85E82F7A309E4CE0_::_A5B892785136489F_
call System.Object _85E82F7A309E4CE0_::_4869D97EE4C04971_()
call System.Object _85E82F7A309E4CE0_::_8BBD9A94715E4A71_(System.Object)
call System.String _85E82F7A309E4CE0_::_5F4C1AEABF6D4B4A_(System.Object)
call System.Boolean _85E82F7A309E4CE0_::_135B7DD042AD4ED3_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 1134843151
stloc.s V_4
ldloc.2 <null>
ldc.i4 -541611
mul <null>
ldloc.s V_4
xor <null>
br.s IL_0036: stloc.3
call System.Object _85E82F7A309E4CE0_::_1B6CA0E97F564E01_()
stloc.1 <null>
ldloc.1 <null>
ldsfld System.Byte[] _85E82F7A309E4CE0_::_A5B892785136489F_
call System.Object _85E82F7A309E4CE0_::_4869D97EE4C04971_()
call System.Object _85E82F7A309E4CE0_::_8BBD9A94715E4A71_(System.Object)
call System.String _85E82F7A309E4CE0_::_5F4C1AEABF6D4B4A_(System.Object)
call System.Boolean _85E82F7A309E4CE0_::_5A04B989EAC74217_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 -48090688
stloc.s V_5
ldloc.2 <null>
ldc.i4 -754485
mul <null>
ldloc.s V_5
xor <null>
br IL_0036: stloc.3
ret <null>
Module Name
server1.exe
Full Name
server1.exe
EntryPoint
System.Void _85E82F7A309E4CE0_::_8FA4B93866254C5C_()
Scope Name
server1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
server1
Assembly Version
2.1.3.9
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
16
Main Method
System.Void _85E82F7A309E4CE0_::_8FA4B93866254C5C_()
Main IL Instruction Count
65
Main IL
nop <null>
call System.String _85E82F7A309E4CE0_::_893818073A474FDD_()
ldc.i4 -2002263336
br.s IL_000D: call System.String <Module>::_784EDDC5CE584513_<System.String>(System.IntPtr)
call System.String <Module>::_784EDDC5CE584513_<System.String>(System.IntPtr)
call System.String _85E82F7A309E4CE0_::_E1EA628C639949E5_(System.String,System.String)
stsfld System.String _85E82F7A309E4CE0_::_3109EA0E084447BA_
ldsfld System.String _85E82F7A309E4CE0_::_3109EA0E084447BA_
call System.Byte[] _85E82F7A309E4CE0_::_BE93724E6EB74286_(System.String)
stsfld System.Byte[] _85E82F7A309E4CE0_::_A5B892785136489F_
call System.Object _85E82F7A309E4CE0_::_F9D6CF050DA645C4_()
stloc.0 <null>
ldc.i4 239919490
stloc.3 <null>
ldc.i4 2004300895
ldc.i4 707457153
ldc.i4 -137285175
mul <null>
ldloc.3 <null>
ldc.i4 -1977679781
ldc.i4 748530179
mul <null>
add <null>
neg <null>
sub <null>
sub <null>
dup <null>
stloc.2 <null>
ldc.i4.4 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_00D7: ret
ldloc.0 <null>
ldsfld System.Byte[] _85E82F7A309E4CE0_::_A5B892785136489F_
call System.Object _85E82F7A309E4CE0_::_4869D97EE4C04971_()
call System.Object _85E82F7A309E4CE0_::_8BBD9A94715E4A71_(System.Object)
call System.String _85E82F7A309E4CE0_::_5F4C1AEABF6D4B4A_(System.Object)
call System.Boolean _85E82F7A309E4CE0_::_135B7DD042AD4ED3_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 1134843151
stloc.s V_4
ldloc.2 <null>
ldc.i4 -541611
mul <null>
ldloc.s V_4
xor <null>
br.s IL_0036: stloc.3
call System.Object _85E82F7A309E4CE0_::_1B6CA0E97F564E01_()
stloc.1 <null>
ldloc.1 <null>
ldsfld System.Byte[] _85E82F7A309E4CE0_::_A5B892785136489F_
call System.Object _85E82F7A309E4CE0_::_4869D97EE4C04971_()
call System.Object _85E82F7A309E4CE0_::_8BBD9A94715E4A71_(System.Object)
call System.String _85E82F7A309E4CE0_::_5F4C1AEABF6D4B4A_(System.Object)
call System.Boolean _85E82F7A309E4CE0_::_5A04B989EAC74217_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 -48090688
stloc.s V_5
ldloc.2 <null>
ldc.i4 -754485
mul <null>
ldloc.s V_5
xor <null>
br IL_0036: stloc.3
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙