Suspicious
Suspect

16a0c325c7f44edb2d39234ef5a2ea57

PE Executable
MD5: 16a0c325c7f44edb2d39234ef5a2ea57
Size: 993.79 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 16a0c325c7f44edb2d39234ef5a2ea57
Sha1 aaa4596019fb243fc401cc6779ac49a5209ba822
Sha256 cff9fc02dfb06bb740609505345e93c40b2b240734913b1122f2ca68a436bc2c
Sha384 5a2cf285b5c36d16cbc8af39429ddebf16f48e4c894d3abc7c69829a79c999c969385edf429a2d5886390c14cf4e3575
Sha512 7fefbb3518c1f1d2bc2fbcd2710636a58ab15eed44a6dafde922a4cc6fdc8b29b45efb5398584a3d0a0d3e6a5bf327215a54dd07c0a027d50577147109191634
SSDeep 12288:tIqET5bM9QQPF33/tRo8ZeDMtfava45R0cCDk8hbIdQJODXkeKRrrkHc:WqY5bM9XFHlRmtacCk8hFJQknRCc
TLSH C025E02913D94B78E8BEAB3494F7022047F0B9CBC636D76FA99860FC4911F5D9581723
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Borgarel.gilrani.rex
rGo7B4pzn_.Resources.resources
693a7dfa1a059a.Resources.resources
e463077d0
[NBF]root.Data
e463077d1
[NBF]root.Data
e463077d10
[NBF]root.Data
e463077d11
[NBF]root.Data
e463077d12
[NBF]root.Data
e463077d13
[NBF]root.Data
e463077d14
[NBF]root.Data
e463077d15
[NBF]root.Data
e463077d16
[NBF]root.Data
e463077d17
[NBF]root.Data
e463077d18
[NBF]root.Data
e463077d19
[NBF]root.Data
e463077d2
[NBF]root.Data
e463077d20
[NBF]root.Data
e463077d21
[NBF]root.Data
e463077d22
[NBF]root.Data
e463077d23
[NBF]root.Data
e463077d24
[NBF]root.Data
e463077d3
[NBF]root.Data
e463077d4
[NBF]root.Data
e463077d5
[NBF]root.Data
e463077d6
[NBF]root.Data
e463077d7
[NBF]root.Data
e463077d8
[NBF]root.Data
e463077d9
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
rGo7B4pzn_
Full Name
rGo7B4pzn_
EntryPoint
System.Void rGo7B4pzn_.3geFD::0Yw_X()
Scope Name
rGo7B4pzn_
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rGo7B4pzn_
Assembly Version
1.28.17.75
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
720
Main Method
System.Void rGo7B4pzn_.3geFD::0Yw_X()
Main IL Instruction Count
15
Main IL
nop <null>
nop <null>
ldstr gilrani.rex
call System.Void rGo7B4pzn_.7Wbxzt0B4aK/Ec4o7smJ.3Dtcn6MzJd0fgw::8bbTGn7j(System.String)
nop <null>
leave.s IL_0023: nop
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0023: nop
nop <null>
ret <null>
Module Name
rGo7B4pzn_
Full Name
rGo7B4pzn_
EntryPoint
System.Void rGo7B4pzn_.3geFD::0Yw_X()
Scope Name
rGo7B4pzn_
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
rGo7B4pzn_
Assembly Version
1.28.17.75
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
720
Main Method
System.Void rGo7B4pzn_.3geFD::0Yw_X()
Main IL Instruction Count
15
Main IL
nop <null>
nop <null>
ldstr gilrani.rex
call System.Void rGo7B4pzn_.7Wbxzt0B4aK/Ec4o7smJ.3Dtcn6MzJd0fgw::8bbTGn7j(System.String)
nop <null>
leave.s IL_0023: nop
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0023: nop
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Borgarel.gilrani.rex
rGo7B4pzn_.Resources.resources
693a7dfa1a059a.Resources.resources
e463077d0
[NBF]root.Data
e463077d1
[NBF]root.Data
e463077d10
[NBF]root.Data
e463077d11
[NBF]root.Data
e463077d12
[NBF]root.Data
e463077d13
[NBF]root.Data
e463077d14
[NBF]root.Data
e463077d15
[NBF]root.Data
e463077d16
[NBF]root.Data
e463077d17
[NBF]root.Data
e463077d18
[NBF]root.Data
e463077d19
[NBF]root.Data
e463077d2
[NBF]root.Data
e463077d20
[NBF]root.Data
e463077d21
[NBF]root.Data
e463077d22
[NBF]root.Data
e463077d23
[NBF]root.Data
e463077d24
[NBF]root.Data
e463077d3
[NBF]root.Data
e463077d4
[NBF]root.Data
e463077d5
[NBF]root.Data
e463077d6
[NBF]root.Data
e463077d7
[NBF]root.Data
e463077d8
[NBF]root.Data
e463077d9
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙