Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5: 1f0836def892a6397fc3e5a87a27d037
Size: 3.55 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 1f0836def892a6397fc3e5a87a27d037
Sha1 b6d1771135c435ab9ea449863a4dba4ca0f6bdb6
Sha256 a00f90db29e2c261c2b6bb00093c43659b577708e8afff72c97f17d41bb06e2e
Sha384 1652918779d7b1e5b68984e8dd2b8ccb3dc168805c1a3da40cd086e986d4cba3b66eeed5f056a6ec6bdd8cead83b95a6
Sha512 8c1c72d5718e392b596e92f9f59b149acb174987d153352b86dd71f8883de466a0b2eb833378f9a8d48ce3b7c37518dbeed0c549d439e7177ec0ba52065b56ae
SSDeep 98304:iukLhse1ZLeiHrPk305UUb+GAHeydKDnnF/FJ:bLevLeiHzk305p+GN5F9
TLSH 0EF5E1027E44CA62F01D1233C3EF454887B4AD516AA6E32B7CBA337D55163A77C0D9EA
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
rkNZF87OJG5DJBL1Ss.ZrL8YBk4eGMt8oaxuS
GL5UtAW44TnWASTWlr.Oy37m9DuLSRf7G1Ou6
Name Value
Module Name
HPkANb3HsdlqvAULGZEyZfM2LKM
Full Name
HPkANb3HsdlqvAULGZEyZfM2LKM
EntryPoint
System.Void IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::PgP7ei2TgY()
Scope Name
HPkANb3HsdlqvAULGZEyZfM2LKM
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mQiouqsOGQjKTJHKI3D5wL
Assembly Version
3.6.1.3
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::PgP7ei2TgY()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void M54rSLp4yXO7YcuMPWM.xblMB8p3pdJKJXKhe0i::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::laJ7ntu7D5
callvirt System.Void lhds4jG3dYs74yG0hmV.mVKH16GUuUGRi8oNJ0W::Eq7TcudeA6()
nop <null>
ret <null>
Module Name
HPkANb3HsdlqvAULGZEyZfM2LKM
Full Name
HPkANb3HsdlqvAULGZEyZfM2LKM
EntryPoint
System.Void IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::PgP7ei2TgY()
Scope Name
HPkANb3HsdlqvAULGZEyZfM2LKM
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mQiouqsOGQjKTJHKI3D5wL
Assembly Version
3.6.1.3
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::PgP7ei2TgY()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void M54rSLp4yXO7YcuMPWM.xblMB8p3pdJKJXKhe0i::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object IvBKL2G7pTwIxEGfqJo.fjJGsKGjrYrNO9vdgj8::laJ7ntu7D5
callvirt System.Void lhds4jG3dYs74yG0hmV.mVKH16GUuUGRi8oNJ0W::Eq7TcudeA6()
nop <null>
ret <null>
Embedded Resources UNKNWOWNsuspect
2huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙