Malicious
Malicious

PE Executable
MD5: 1f0836def892a6397fc3e5a87a27d037
Size: 3.55 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 1f0836def892a6397fc3e5a87a27d037
Sha1 b6d1771135c435ab9ea449863a4dba4ca0f6bdb6
Sha256 a00f90db29e2c261c2b6bb00093c43659b577708e8afff72c97f17d41bb06e2e
Sha384 1652918779d7b1e5b68984e8dd2b8ccb3dc168805c1a3da40cd086e986d4cba3b66eeed5f056a6ec6bdd8cead83b95a6
Sha512 8c1c72d5718e392b596e92f9f59b149acb174987d153352b86dd71f8883de466a0b2eb833378f9a8d48ce3b7c37518dbeed0c549d439e7177ec0ba52065b56ae
SSDeep 98304:iukLhse1ZLeiHrPk305UUb+GAHeydKDnnF/FJ:bLevLeiHzk305p+GN5F9
TLSH 0EF5E1027E44CA62F01D1233C3EF454887B4AD516AA6E32B7CBA337D55163A77C0D9EA
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
rkNZF87OJG5DJBL1Ss.ZrL8YBk4eGMt8oaxuS
GL5UtAW44TnWASTWlr.Oy37m9DuLSRf7G1Ou6
Name Value
Module Name
HPkANb3HsdlqvAULGZEyZfM2LKM
Full Name
HPkANb3HsdlqvAULGZEyZfM2LKM
EntryPoint
System.Void IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::PgP7ei2TgY()
Scope Name
HPkANb3HsdlqvAULGZEyZfM2LKM
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mQiouqsOGQjKTJHKI3D5wL
Assembly Version
3.6.1.3
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::PgP7ei2TgY()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void M54rSLp4yXO7YcuMPWM.xblMB8p3pdJKJXKhe0i::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::laJ7ntu7D5
callvirt System.Void lhds4jG3dYs74yG0hmV.mVKH16GUuUGRi8oNJ0W::Eq7TcudeA6()
nop <null>
ret <null>
Module Name
HPkANb3HsdlqvAULGZEyZfM2LKM
Full Name
HPkANb3HsdlqvAULGZEyZfM2LKM
EntryPoint
System.Void IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::PgP7ei2TgY()
Scope Name
HPkANb3HsdlqvAULGZEyZfM2LKM
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mQiouqsOGQjKTJHKI3D5wL
Assembly Version
3.6.1.3
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::PgP7ei2TgY()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void M54rSLp4yXO7YcuMPWM.xblMB8p3pdJKJXKhe0i::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::laJ7ntu7D5
callvirt System.Void lhds4jG3dYs74yG0hmV.mVKH16GUuUGRi8oNJ0W::Eq7TcudeA6()
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
rkNZF87OJG5DJBL1Ss.ZrL8YBk4eGMt8oaxuS
GL5UtAW44TnWASTWlr.Oy37m9DuLSRf7G1Ou6
No malware configuration was found at this point.
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
1f0836def892a6397fc3e5a87a27d037
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
1f0836def892a6397fc3e5a87a27d037
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙