Suspicious
Suspect

PE Executable
MD5: 168131ce449d092ea8cb6f9732a085f3
Size: 3.27 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 168131ce449d092ea8cb6f9732a085f3
Sha1 85fa3f4cee9ddb823b47ced286bec34680b4ac64
Sha256 5f5f33d963ef205ea5ccf35dd75105c99572dba9ec8ed66d8268481ad56f274d
Sha384 db08500565e3c3a93be910a97118ca653ef936b30acd236df2293221262a7824c3f76586767f3d0ab848ce1d9f0be0f0
Sha512 2bf8ea227e318949155ccb4abe610670f7b2f6636493228b7290827141a866547f54d23bd9cf07a4b581c4234a8f5da12d09093d83f09d48b624a770ba0340ad
SSDeep 49152:7vXe821/aQWl8P0lSk3aKA3Z+nLUPdLBxoQoGdUTHHB72eh2NT:7vO821/aQWl8P0lSk3DA3Z+noPdX
TLSH B2E55B1437F85E33E16AD673D9B05016A3F1F82AF363EB1B518267BA1C53B508C41AA7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void ⷔ匱̀䨇䪋뾔࣓ࣼ캂䓒津儾铌軥ꥍ⍓ℙ煶斧::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void ⷔ匱̀䨇䪋뾔࣓ࣼ캂䓒津儾铌軥ꥍ⍓ℙ煶斧::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void ⷔ匱̀䨇䪋뾔࣓ࣼ캂䓒津儾铌軥ꥍ⍓ℙ煶斧::蟋Ṡ⡀溹猣맪ݿ쓯ബ❖惠ﮐ럀ꨑ乖몫뾎蒔(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ⷔ匱̀䨇䪋뾔࣓ࣼ캂䓒津儾铌軥ꥍ⍓ℙ煶斧::쏽鄝롱囆≯죁퀁蝍蜻�ሙ攗䵳澩筟朂隅饼(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 댸䎋ꂌ慙⴨ɕ搥ƿ嘖쥪훁罽冱庄䗶飩㟫赘碗::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void ⷔ匱̀䨇䪋뾔࣓ࣼ캂䓒津儾铌軥ꥍ⍓ℙ煶斧::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
11123
Main Method
System.Void ⷔ匱̀䨇䪋뾔࣓ࣼ캂䓒津儾铌軥ꥍ⍓ℙ煶斧::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void ⷔ匱̀䨇䪋뾔࣓ࣼ캂䓒津儾铌軥ꥍ⍓ℙ煶斧::蟋Ṡ⡀溹猣맪ݿ쓯ബ❖惠ﮐ럀ꨑ乖몫뾎蒔(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ⷔ匱̀䨇䪋뾔࣓ࣼ캂䓒津儾铌軥ꥍ⍓ℙ煶斧::쏽鄝롱囆≯죁퀁蝍蜻�ሙ攗䵳澩筟朂隅饼(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 댸䎋ꂌ慙⴨ɕ搥ƿ嘖쥪훁罽冱庄䗶飩㟫赘碗::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙