Suspicious
Suspect

PE Executable
MD5: 16fbbb3402f4546c544d3eab8c030524
Size: 1.85 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 16fbbb3402f4546c544d3eab8c030524
Sha1 0b03c5b5a8991eeee426bbc85cd3d91b53f76ed1
Sha256 9019276cf50b5e8397a04c81e75faf35308f2dd7b480db9a060e1c50e66678f2
Sha384 24d09366ab8e2e4770394e65355a758178f6831d196b3abd27441c5ac848142d23ca1a76aae3b8634eec55cb95c5511e
Sha512 74956af91ca12fadbc632cc0549137ccab4dcd3937864c0714f6349ed933c09b774e37e9a9a57448377a5430dbc642bd984431e5c9a8ce518c53e93dc95961cf
SSDeep 49152:gWPYt89P76xlhM+n4UR3CF2Qgr3X4WTm7:DILLn483Cdgr3XRTm
TLSH 59853312D15546BAEF73D9F6BAF2DDD3A7468A034731A101EC3E12D874531816BEE328
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
a
Name Value
Module Name
temploader.exe
Full Name
temploader.exe
EntryPoint
System.Void a.a::Main()
Scope Name
temploader.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
temploader
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
3
Main Method
System.Void a.a::Main()
Main IL Instruction Count
37
Main IL
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
ldstr U4ou427B2f+G2QJKm4Snjg==
ldstr L930W6/7+mDXFdacKNnsAMeAHdxq2X/OOnMDs1Uv0nA=
ldstr gNe+YBRzM1RikswVbcM0CA==
call System.String 籣嶅첲༖㊸ᠱ풒疙밃::瓈舗ꂛ檇诶좸٭秔஭༷(System.String,System.String,System.String)
callvirt System.IO.Stream System.Reflection.Assembly::GetManifestResourceStream(System.String)
stloc.0 <null>
newobj System.Void System.IO.MemoryStream::.ctor()
stloc.1 <null>
ldloc.0 <null>
ldc.i4.0 <null>
newobj System.Void System.IO.Compression.DeflateStream::.ctor(System.IO.Stream,System.IO.Compression.CompressionMode)
stloc.2 <null>
ldloc.2 <null>
ldloc.1 <null>
callvirt System.Void System.IO.Stream::CopyTo(System.IO.Stream)
leave IL_0046: ldloc.1
ldloc.2 <null>
brfalse IL_0045: endfinally
ldloc.2 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ldloc.1 <null>
callvirt System.Byte[] System.IO.MemoryStream::ToArray()
call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
callvirt System.Reflection.MethodInfo System.Reflection.Assembly::get_EntryPoint()
ldnull <null>
ldnull <null>
callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[])
pop <null>
leave IL_0070: ret
ldloc.0 <null>
brfalse IL_006F: endfinally
ldloc.0 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ret <null>
Module Name
temploader.exe
Full Name
temploader.exe
EntryPoint
System.Void a.a::Main()
Scope Name
temploader.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
temploader
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
3
Main Method
System.Void a.a::Main()
Main IL Instruction Count
37
Main IL
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
ldstr U4ou427B2f+G2QJKm4Snjg==
ldstr L930W6/7+mDXFdacKNnsAMeAHdxq2X/OOnMDs1Uv0nA=
ldstr gNe+YBRzM1RikswVbcM0CA==
call System.String 籣嶅첲༖㊸ᠱ풒疙밃::瓈舗ꂛ檇诶좸٭秔஭༷(System.String,System.String,System.String)
callvirt System.IO.Stream System.Reflection.Assembly::GetManifestResourceStream(System.String)
stloc.0 <null>
newobj System.Void System.IO.MemoryStream::.ctor()
stloc.1 <null>
ldloc.0 <null>
ldc.i4.0 <null>
newobj System.Void System.IO.Compression.DeflateStream::.ctor(System.IO.Stream,System.IO.Compression.CompressionMode)
stloc.2 <null>
ldloc.2 <null>
ldloc.1 <null>
callvirt System.Void System.IO.Stream::CopyTo(System.IO.Stream)
leave IL_0046: ldloc.1
ldloc.2 <null>
brfalse IL_0045: endfinally
ldloc.2 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ldloc.1 <null>
callvirt System.Byte[] System.IO.MemoryStream::ToArray()
call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
callvirt System.Reflection.MethodInfo System.Reflection.Assembly::get_EntryPoint()
ldnull <null>
ldnull <null>
callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[])
pop <null>
leave IL_0070: ret
ldloc.0 <null>
brfalse IL_006F: endfinally
ldloc.0 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWNsuspect
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
a
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
1huhuhuhu
16fbbb3402f4546c544d3eab8c030524
Suspicious Type Names (1-2 chars) UNKNWOWNsuspect
1huhuhuhu
16fbbb3402f4546c544d3eab8c030524
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙