Suspicious
Suspect

21eb9600a3a6f166fec7f0ad6075318e

PE Executable
|
MD5: 21eb9600a3a6f166fec7f0ad6075318e
|
Size: 1.63 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
21eb9600a3a6f166fec7f0ad6075318e
Sha1
e808587a3ab86b0c8954d473dc5c94d440439a6f
Sha256
6bf81a58f47093727e85a5175d3b7042384159ce7088fa94b4476bda09ea401e
Sha384
2964dd9e161c984e38b43c9d5de6522df1d2c3b916baf6b9c022532cac2eba3fccfdfbd6ee5bacd76afad18f3e7d27d2
Sha512
f01b11de0d7bfa0bd97476de3757c2ae44270dc8747601360a27889769d99665e128c63ca798f413b3f47b697db987d9debe03a5566de88d35898dda6a8bde6e
SSDeep
24576:YO5nKChjGa7Dck7K8O/5vJBeyy0WI8NM1xQZeXgrorB2qF:YmKSGWDB7aBZvYe1k3rorB2q
TLSH
C275E01533E85E18F5BE4B78D0B5052803F6BA0BFB3AEB1E7E4505EE1C12B509986763

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Da3c1gxP.g.resources
Da3c1gxP.Resources.resources
477fcd9c8e782e.Resources.resources
6ae4ed850
[NBF]root.Data
6ae4ed851
[NBF]root.Data
6ae4ed8510
[NBF]root.Data
6ae4ed8511
[NBF]root.Data
6ae4ed8512
[NBF]root.Data
6ae4ed8513
[NBF]root.Data
6ae4ed8514
[NBF]root.Data
6ae4ed8515
[NBF]root.Data
6ae4ed8516
[NBF]root.Data
6ae4ed8517
[NBF]root.Data
6ae4ed8518
[NBF]root.Data
6ae4ed8519
[NBF]root.Data
6ae4ed852
[NBF]root.Data
6ae4ed8520
[NBF]root.Data
6ae4ed8521
[NBF]root.Data
6ae4ed8522
[NBF]root.Data
6ae4ed8523
[NBF]root.Data
6ae4ed8524
[NBF]root.Data
6ae4ed8525
[NBF]root.Data
6ae4ed8526
[NBF]root.Data
6ae4ed8527
[NBF]root.Data
6ae4ed8528
[NBF]root.Data
6ae4ed8529
[NBF]root.Data
6ae4ed853
[NBF]root.Data
6ae4ed8530
[NBF]root.Data
6ae4ed8531
[NBF]root.Data
6ae4ed8532
[NBF]root.Data
6ae4ed8533
[NBF]root.Data
6ae4ed8534
[NBF]root.Data
6ae4ed8535
[NBF]root.Data
6ae4ed8536
[NBF]root.Data
6ae4ed8537
[NBF]root.Data
6ae4ed8538
[NBF]root.Data
6ae4ed8539
[NBF]root.Data
6ae4ed854
[NBF]root.Data
6ae4ed8540
[NBF]root.Data
6ae4ed8541
[NBF]root.Data
6ae4ed8542
[NBF]root.Data
6ae4ed8543
[NBF]root.Data
6ae4ed8544
[NBF]root.Data
6ae4ed8545
[NBF]root.Data
6ae4ed8546
[NBF]root.Data
6ae4ed8547
[NBF]root.Data
6ae4ed8548
[NBF]root.Data
6ae4ed8549
[NBF]root.Data
6ae4ed855
[NBF]root.Data
6ae4ed8550
[NBF]root.Data
6ae4ed8551
[NBF]root.Data
6ae4ed8552
[NBF]root.Data
6ae4ed8553
[NBF]root.Data
6ae4ed8554
[NBF]root.Data
6ae4ed856
[NBF]root.Data
6ae4ed857
[NBF]root.Data
6ae4ed858
[NBF]root.Data
6ae4ed859
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Da3c1gxP

Full Name

Da3c1gxP

EntryPoint

System.Void Da3c1gxP.Hfk21Dqyz/mXo8C3tj7.os4Zq0Wmtp2B::5txPn7NyLmd90T()

Scope Name

Da3c1gxP

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Da3c1gxP

Assembly Version

2.28.17.184

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1083

Main Method

System.Void Da3c1gxP.Hfk21Dqyz/mXo8C3tj7.os4Zq0Wmtp2B::5txPn7NyLmd90T()

Main IL Instruction Count

121

Main IL

nop <null> nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldstr SoilMoistureMonitor_v1 stloc.0 <null> ldc.i4.0 <null> stloc.1 <null> newobj System.Void Da3c1gxP.Hfk21Dqyz::.ctor() stloc.2 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.2 <null> stelem.ref <null> dup <null> stloc.s V_4 ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_5 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_6 ldloc.s V_5 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_005A: ldloc.s V_4 br.s IL_0078: ldloc.s V_6 ldloc.s V_4 ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken Da3c1gxP.Hfk21Dqyz call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass Da3c1gxP.Hfk21Dqyz stloc.2 <null> ldloc.s V_6 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.3 <null> leave IL_0108: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_7 nop <null> nop <null> ldc.i4.3 <null> stloc.s V_8 ldc.i4.0 <null> stloc.s V_9 ldc.i4.0 <null> stloc.s V_10 ldc.i4.s 25 stloc.s V_11 br.s IL_00C4: ldloc.s V_11 ldloc.s V_11 ldc.i4.3 <null> mul.ovf <null> stloc.s V_11 ldloc.s V_11 ldc.i4.s 25 cgt <null> stloc.s V_14 ldloc.s V_14 brfalse.s IL_00C2: nop ldc.i4.s 25 stloc.s V_11 ldstr resources/gagecharts call System.Byte[] Da3c1gxP.LaserLay.Core.Zxa4s3Cndp6F::8Yitgg5Q3oZs(System.String) stloc.s V_12 br.s IL_00D2: ldloc.s V_9 nop <null> nop <null> ldloc.s V_11 ldc.i4.s 25 rem <null> ldc.i4.0 <null> ceq <null> stloc.s V_15 ldloc.s V_15 brtrue.s IL_009E: ldloc.s V_11 ldloc.s V_9 stloc.s V_13 ldloc.s V_12 castclass System.Byte[] call System.Void Da3c1gxP.MasterMimic.Core.6LcxZfm79Y::0tsWYf7kyQg2(System.Byte[]) nop <null> leave.s IL_00F5: leave.s IL_0100 dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_16 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00F5: leave.s IL_0100 leave.s IL_0100: nop nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> endfinally <null> nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0108: nop nop <null> ret <null>

Module Name

Da3c1gxP

Full Name

Da3c1gxP

EntryPoint

System.Void Da3c1gxP.Hfk21Dqyz/mXo8C3tj7.os4Zq0Wmtp2B::5txPn7NyLmd90T()

Scope Name

Da3c1gxP

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Da3c1gxP

Assembly Version

2.28.17.184

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1083

Main Method

System.Void Da3c1gxP.Hfk21Dqyz/mXo8C3tj7.os4Zq0Wmtp2B::5txPn7NyLmd90T()

Main IL Instruction Count

121

Main IL

nop <null> nop <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldstr SoilMoistureMonitor_v1 stloc.0 <null> ldc.i4.0 <null> stloc.1 <null> newobj System.Void Da3c1gxP.Hfk21Dqyz::.ctor() stloc.2 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.2 <null> stelem.ref <null> dup <null> stloc.s V_4 ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_5 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_6 ldloc.s V_5 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_005A: ldloc.s V_4 br.s IL_0078: ldloc.s V_6 ldloc.s V_4 ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken Da3c1gxP.Hfk21Dqyz call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass Da3c1gxP.Hfk21Dqyz stloc.2 <null> ldloc.s V_6 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.3 <null> leave IL_0108: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_7 nop <null> nop <null> ldc.i4.3 <null> stloc.s V_8 ldc.i4.0 <null> stloc.s V_9 ldc.i4.0 <null> stloc.s V_10 ldc.i4.s 25 stloc.s V_11 br.s IL_00C4: ldloc.s V_11 ldloc.s V_11 ldc.i4.3 <null> mul.ovf <null> stloc.s V_11 ldloc.s V_11 ldc.i4.s 25 cgt <null> stloc.s V_14 ldloc.s V_14 brfalse.s IL_00C2: nop ldc.i4.s 25 stloc.s V_11 ldstr resources/gagecharts call System.Byte[] Da3c1gxP.LaserLay.Core.Zxa4s3Cndp6F::8Yitgg5Q3oZs(System.String) stloc.s V_12 br.s IL_00D2: ldloc.s V_9 nop <null> nop <null> ldloc.s V_11 ldc.i4.s 25 rem <null> ldc.i4.0 <null> ceq <null> stloc.s V_15 ldloc.s V_15 brtrue.s IL_009E: ldloc.s V_11 ldloc.s V_9 stloc.s V_13 ldloc.s V_12 castclass System.Byte[] call System.Void Da3c1gxP.MasterMimic.Core.6LcxZfm79Y::0tsWYf7kyQg2(System.Byte[]) nop <null> leave.s IL_00F5: leave.s IL_0100 dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_16 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00F5: leave.s IL_0100 leave.s IL_0100: nop nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> endfinally <null> nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0108: nop nop <null> ret <null>

21eb9600a3a6f166fec7f0ad6075318e (1.63 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Da3c1gxP.g.resources
Da3c1gxP.Resources.resources
477fcd9c8e782e.Resources.resources
6ae4ed850
[NBF]root.Data
6ae4ed851
[NBF]root.Data
6ae4ed8510
[NBF]root.Data
6ae4ed8511
[NBF]root.Data
6ae4ed8512
[NBF]root.Data
6ae4ed8513
[NBF]root.Data
6ae4ed8514
[NBF]root.Data
6ae4ed8515
[NBF]root.Data
6ae4ed8516
[NBF]root.Data
6ae4ed8517
[NBF]root.Data
6ae4ed8518
[NBF]root.Data
6ae4ed8519
[NBF]root.Data
6ae4ed852
[NBF]root.Data
6ae4ed8520
[NBF]root.Data
6ae4ed8521
[NBF]root.Data
6ae4ed8522
[NBF]root.Data
6ae4ed8523
[NBF]root.Data
6ae4ed8524
[NBF]root.Data
6ae4ed8525
[NBF]root.Data
6ae4ed8526
[NBF]root.Data
6ae4ed8527
[NBF]root.Data
6ae4ed8528
[NBF]root.Data
6ae4ed8529
[NBF]root.Data
6ae4ed853
[NBF]root.Data
6ae4ed8530
[NBF]root.Data
6ae4ed8531
[NBF]root.Data
6ae4ed8532
[NBF]root.Data
6ae4ed8533
[NBF]root.Data
6ae4ed8534
[NBF]root.Data
6ae4ed8535
[NBF]root.Data
6ae4ed8536
[NBF]root.Data
6ae4ed8537
[NBF]root.Data
6ae4ed8538
[NBF]root.Data
6ae4ed8539
[NBF]root.Data
6ae4ed854
[NBF]root.Data
6ae4ed8540
[NBF]root.Data
6ae4ed8541
[NBF]root.Data
6ae4ed8542
[NBF]root.Data
6ae4ed8543
[NBF]root.Data
6ae4ed8544
[NBF]root.Data
6ae4ed8545
[NBF]root.Data
6ae4ed8546
[NBF]root.Data
6ae4ed8547
[NBF]root.Data
6ae4ed8548
[NBF]root.Data
6ae4ed8549
[NBF]root.Data
6ae4ed855
[NBF]root.Data
6ae4ed8550
[NBF]root.Data
6ae4ed8551
[NBF]root.Data
6ae4ed8552
[NBF]root.Data
6ae4ed8553
[NBF]root.Data
6ae4ed8554
[NBF]root.Data
6ae4ed856
[NBF]root.Data
6ae4ed857
[NBF]root.Data
6ae4ed858
[NBF]root.Data
6ae4ed859
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙