Suspicious
Suspect

1f1ae04a8d25417ee803fdc69d154b1d

PE Executable
MD5: 1f1ae04a8d25417ee803fdc69d154b1d
Size: 749.06 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 1f1ae04a8d25417ee803fdc69d154b1d
Sha1 042b1fc885c8eb47c2390a525dc30ec04619ed90
Sha256 d9f9afdce2b6d94cbb0155b60bfc8e8bad8de077f64dec67e3c1b47eab27bb02
Sha384 9f72c9beccaa79f3a10d84ceb05b397573bbff2cc75f7f6fadb4fb24ac52f33393a4ff47c5e460fdaab5f7c98f879b6e
Sha512 d6bacc2ce2591d301d1d03dbbe233d75f9447ebc2e694f35d5fd3532130c542caf4ba2f6d4d7dc696a9d9bda2bd86003d10b82b7c53b8c26186f04da3c7caf7e
SSDeep 12288:4ZcPSnTc6ye1DO8gTWUUVOrMjoFS7uZAvxv5gCPTKW9ky:ch1ydUVOrMjrqZA5v5RPWJy
TLSH DEF4124DFBA4E611C19D077B94A3A501D0538813F1F2F16EAD8A2CE56F25788C18E79F
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
nwpJ.exe
Full Name
nwpJ.exe
EntryPoint
System.Void SecureMode.Program::Main()
Scope Name
nwpJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nwpJ
Assembly Version
1.6.1908.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
2
Main Method
System.Void SecureMode.Program::Main()
Main IL Instruction Count
27
Main IL
ldsfld System.Char[] SecureMode.AdvancedForm20::Ⴍ
stloc.2 <null>
ldc.i4.4 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void SecureMode.ProfessionalForm65::Ⴐ()
ldc.i4 299
ldc.i4 325
call System.Void SecureMode.ProfessionalForm88::Ⴀ(System.Int32,System.Int16)
ldc.i4.0 <null>
ldc.i4 538
ldc.i4 519
call System.Void SecureMode.ProfessionalForm53::Ⴄ(System.Boolean,System.Char,System.Int16)
ldloc.2 <null>
ldc.i4.s 124
ldelem.u2 <null>
ldc.i4 58012
sub <null>
stloc.1 <null>
br.s IL_0008: ldloc.1
newobj System.Void SecureMode.ProfessionalForm53::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void SecureMode.Program::Main()
pop <null>
ret <null>
Module Name
nwpJ.exe
Full Name
nwpJ.exe
EntryPoint
System.Void SecureMode.Program::Main()
Scope Name
nwpJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
nwpJ
Assembly Version
1.6.1908.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
2
Main Method
System.Void SecureMode.Program::Main()
Main IL Instruction Count
27
Main IL
ldsfld System.Char[] SecureMode.AdvancedForm20::Ⴍ
stloc.2 <null>
ldc.i4.4 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void SecureMode.ProfessionalForm65::Ⴐ()
ldc.i4 299
ldc.i4 325
call System.Void SecureMode.ProfessionalForm88::Ⴀ(System.Int32,System.Int16)
ldc.i4.0 <null>
ldc.i4 538
ldc.i4 519
call System.Void SecureMode.ProfessionalForm53::Ⴄ(System.Boolean,System.Char,System.Int16)
ldloc.2 <null>
ldc.i4.s 124
ldelem.u2 <null>
ldc.i4 58012
sub <null>
stloc.1 <null>
br.s IL_0008: ldloc.1
newobj System.Void SecureMode.ProfessionalForm53::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void SecureMode.Program::Main()
pop <null>
ret <null>
Embedded Resources UNKNWOWN
0huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWN
0huhuhuhu
1f1ae04a8d25417ee803fdc69d154b1d
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
1f1ae04a8d25417ee803fdc69d154b1d
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙