Suspicious
Suspect

1bf0dde88b64ddf3208f56459366e680

PE Executable
|
MD5: 1bf0dde88b64ddf3208f56459366e680
|
Size: 1.39 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
1bf0dde88b64ddf3208f56459366e680
Sha1
2c6241537a4d49e9084b5c391fc0421bb0047b4f
Sha256
db710d8b8a05aa6b73f401df24f73bb5b2e390921cb9e05a2fa4bfb8b9622447
Sha384
2b9f2165d72f5043c1771590d57472540ef38e12300e44f1133e4810c3b9c892ed013c008403f70f3483d71fc32186af
Sha512
00fd5748c022daf5945e295fcccb26a4b2506b6a7c74dba6d975cfc521ca3c108f45a521389f4d14183452a4ddc4d4278ce53a56d4fa22f6f57ff3cfc361fd7f
SSDeep
24576:7gdzN67rUBVia9FWqjf5ZmiLf1Djmzd3LXvAQJ5bmSYAXCK/GR5:7gE4FFWqdciLf1nmZbXIQJ5bhYtV
TLSH
9A55F21A16C16BA4E07ECB78E7B8009943F0661FE722E7AF3D5C12F49E2174567532A3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
3ZjgFci0s6mK.g.resources
3ZjgFci0s6mK.Resources.resources
a99b990e1bab69.Resources.resources
343c4ec10
[NBF]root.Data
343c4ec11
[NBF]root.Data
343c4ec110
[NBF]root.Data
343c4ec111
[NBF]root.Data
343c4ec112
[NBF]root.Data
343c4ec113
[NBF]root.Data
343c4ec114
[NBF]root.Data
343c4ec115
[NBF]root.Data
343c4ec116
[NBF]root.Data
343c4ec117
[NBF]root.Data
343c4ec118
[NBF]root.Data
343c4ec119
[NBF]root.Data
343c4ec12
[NBF]root.Data
343c4ec120
[NBF]root.Data
343c4ec121
[NBF]root.Data
343c4ec122
[NBF]root.Data
343c4ec123
[NBF]root.Data
343c4ec124
[NBF]root.Data
343c4ec125
[NBF]root.Data
343c4ec126
[NBF]root.Data
343c4ec127
[NBF]root.Data
343c4ec128
[NBF]root.Data
343c4ec129
[NBF]root.Data
343c4ec13
[NBF]root.Data
343c4ec130
[NBF]root.Data
343c4ec131
[NBF]root.Data
343c4ec132
[NBF]root.Data
343c4ec133
[NBF]root.Data
343c4ec134
[NBF]root.Data
343c4ec135
[NBF]root.Data
343c4ec136
[NBF]root.Data
343c4ec137
[NBF]root.Data
343c4ec138
[NBF]root.Data
343c4ec139
[NBF]root.Data
343c4ec14
[NBF]root.Data
343c4ec140
[NBF]root.Data
343c4ec141
[NBF]root.Data
343c4ec142
[NBF]root.Data
343c4ec15
[NBF]root.Data
343c4ec16
[NBF]root.Data
343c4ec17
[NBF]root.Data
343c4ec18
[NBF]root.Data
343c4ec19
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

3ZjgFci0s6mK

Full Name

3ZjgFci0s6mK

EntryPoint

System.Void 3ZjgFci0s6mK.Nti0j6Zt9FopPd/Wf6b5.Aqt1i6MrXy3a7g::9FwoSx()

Scope Name

3ZjgFci0s6mK

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

3ZjgFci0s6mK

Assembly Version

18.29.44.84

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

912

Main Method

System.Void 3ZjgFci0s6mK.Nti0j6Zt9FopPd/Wf6b5.Aqt1i6MrXy3a7g::9FwoSx()

Main IL Instruction Count

76

Main IL

nop <null> nop <null> ldc.i4.s 24 stloc.0 <null> ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newarr System.Object stloc.1 <null> ldc.i4 9032078 stloc.2 <null> ldloc.1 <null> ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldstr resources/aximone call System.Byte[] 3ZjgFci0s6mK.eFf1Jc/dQc7o0.6nyZg::5gnSW0nrbKk47q(System.String) ldloc.2 <null> call System.Object 3ZjgFci0s6mK.Ptb1n0CpqRg7::9JjwcsR4a3yQeN(System.Byte[],System.Int32) ldnull <null> ldstr ToArray ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stelem.ref <null> ldloc.1 <null> ldloc.0 <null> ldc.i4.6 <null> sub.ovf <null> ldtoken System.Reflection.Assembly call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) ldstr Load ldc.i4.s 24 ldnull <null> ldc.i4.1 <null> newarr System.Type dup <null> ldc.i4.0 <null> ldtoken System.Byte[] call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) stelem.ref <null> ldnull <null> call System.Reflection.MethodInfo System.Type::GetMethod(System.String,System.Reflection.BindingFlags,System.Reflection.Binder,System.Type[],System.Reflection.ParameterModifier[]) ldnull <null> ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldloc.1 <null> ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldelem.ref <null> stelem.ref <null> callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stelem.ref <null> ldloc.1 <null> ldloc.0 <null> call System.Void 3ZjgFci0s6mK.Ywd5k9z/1y_AyEq6t.7SgqM::6e_MdG(System.Object[],System.Int32) nop <null> leave.s IL_00A6: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.3 <null> nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00A6: nop nop <null> ret <null>

Module Name

3ZjgFci0s6mK

Full Name

3ZjgFci0s6mK

EntryPoint

System.Void 3ZjgFci0s6mK.Nti0j6Zt9FopPd/Wf6b5.Aqt1i6MrXy3a7g::9FwoSx()

Scope Name

3ZjgFci0s6mK

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

3ZjgFci0s6mK

Assembly Version

18.29.44.84

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

912

Main Method

System.Void 3ZjgFci0s6mK.Nti0j6Zt9FopPd/Wf6b5.Aqt1i6MrXy3a7g::9FwoSx()

Main IL Instruction Count

76

Main IL

nop <null> nop <null> ldc.i4.s 24 stloc.0 <null> ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newarr System.Object stloc.1 <null> ldc.i4 9032078 stloc.2 <null> ldloc.1 <null> ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldstr resources/aximone call System.Byte[] 3ZjgFci0s6mK.eFf1Jc/dQc7o0.6nyZg::5gnSW0nrbKk47q(System.String) ldloc.2 <null> call System.Object 3ZjgFci0s6mK.Ptb1n0CpqRg7::9JjwcsR4a3yQeN(System.Byte[],System.Int32) ldnull <null> ldstr ToArray ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stelem.ref <null> ldloc.1 <null> ldloc.0 <null> ldc.i4.6 <null> sub.ovf <null> ldtoken System.Reflection.Assembly call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) ldstr Load ldc.i4.s 24 ldnull <null> ldc.i4.1 <null> newarr System.Type dup <null> ldc.i4.0 <null> ldtoken System.Byte[] call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) stelem.ref <null> ldnull <null> call System.Reflection.MethodInfo System.Type::GetMethod(System.String,System.Reflection.BindingFlags,System.Reflection.Binder,System.Type[],System.Reflection.ParameterModifier[]) ldnull <null> ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldloc.1 <null> ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldelem.ref <null> stelem.ref <null> callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stelem.ref <null> ldloc.1 <null> ldloc.0 <null> call System.Void 3ZjgFci0s6mK.Ywd5k9z/1y_AyEq6t.7SgqM::6e_MdG(System.Object[],System.Int32) nop <null> leave.s IL_00A6: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.3 <null> nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00A6: nop nop <null> ret <null>

1bf0dde88b64ddf3208f56459366e680 (1.39 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙