Suspicious
Suspect

PE Executable
MD5: 23fcfd93b163cf1ebc67a18197bca5d9
Size: 1.04 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 23fcfd93b163cf1ebc67a18197bca5d9
Sha1 ee7ff78f335849ed607ca3240d5e0b22e8fdabcb
Sha256 60a26437468391932cb6d87b57e7ab89f22ffabe4bb199a5cc7ecbe1fa931f71
Sha384 97180d0cc7d964ad54a4660fee47eea11932b7b22afea417f1aab6063b32fc293eca5fb500601953d746f272da9c38ba
Sha512 c499658c8e1d70934439fb10e72cb23dd39669c015e015305d93a742963206f2b699bf6fb110773e8072384ef6a503cff51f567aaf5677233b2b744adfbdeef3
SSDeep 12288:ALK1IMH6uRTF/sqb4+7GyhZ1ISX0Bf/hAMwn70KdrtX7GwQvOl/RLRxJ23LuoZx:EonTF/fb39Z1JXJ0+rJGw8Ol1c3LuG
TLSH B925E11113E85AA8F4BE9B788DB5451547F1F807E72EDF5E6E8980EE0C71BC08A56323
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
0QfqcbE3Ko2gkP.g.resources
0QfqcbE3Ko2gkP.Resources.resources
79b0df113c3070.Resources.resources
ad5190cd0
[NBF]root.Data
ad5190cd1
[NBF]root.Data
ad5190cd10
[NBF]root.Data
ad5190cd11
[NBF]root.Data
ad5190cd12
[NBF]root.Data
ad5190cd13
[NBF]root.Data
ad5190cd14
[NBF]root.Data
ad5190cd15
[NBF]root.Data
ad5190cd16
[NBF]root.Data
ad5190cd17
[NBF]root.Data
ad5190cd18
[NBF]root.Data
ad5190cd19
[NBF]root.Data
ad5190cd2
[NBF]root.Data
ad5190cd20
[NBF]root.Data
ad5190cd21
[NBF]root.Data
ad5190cd22
[NBF]root.Data
ad5190cd23
[NBF]root.Data
ad5190cd3
[NBF]root.Data
ad5190cd4
[NBF]root.Data
ad5190cd5
[NBF]root.Data
ad5190cd6
[NBF]root.Data
ad5190cd7
[NBF]root.Data
ad5190cd8
[NBF]root.Data
ad5190cd9
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
0QfqcbE3Ko2gkP
Full Name
0QfqcbE3Ko2gkP
EntryPoint
System.Void 0QfqcbE3Ko2gkP.1FdyRgb3/0Nmomc4C2rXiq.oz2A_4Rs5::Gfj5y9kPRn4s3()
Scope Name
0QfqcbE3Ko2gkP
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
0QfqcbE3Ko2gkP
Assembly Version
28.11.45.136
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1089
Main Method
System.Void 0QfqcbE3Ko2gkP.1FdyRgb3/0Nmomc4C2rXiq.oz2A_4Rs5::Gfj5y9kPRn4s3()
Main IL Instruction Count
39
Main IL
nop <null>
nop <null>
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
callvirt System.String System.Reflection.Assembly::get_Location()
call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String)
callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion()
stloc.0 <null>
ldloc.0 <null>
call System.Boolean System.String::IsNullOrEmpty(System.String)
stloc.3 <null>
ldloc.3 <null>
brfalse.s IL_0027: ldc.i4.s 100
ldstr 1.6.4.9
stloc.0 <null>
ldc.i4.s 100
call System.Void System.Threading.Thread::Sleep(System.Int32)
nop <null>
ldc.i4.s 26
call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder)
ldstr AppConfig.dat
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.1 <null>
newobj System.Void 0QfqcbE3Ko2gkP.sz4MbJ::.ctor()
stloc.2 <null>
ldloc.2 <null>
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
leave.s IL_0067: nop
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.s V_4
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0067: nop
nop <null>
ret <null>
Module Name
0QfqcbE3Ko2gkP
Full Name
0QfqcbE3Ko2gkP
EntryPoint
System.Void 0QfqcbE3Ko2gkP.1FdyRgb3/0Nmomc4C2rXiq.oz2A_4Rs5::Gfj5y9kPRn4s3()
Scope Name
0QfqcbE3Ko2gkP
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
0QfqcbE3Ko2gkP
Assembly Version
28.11.45.136
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1089
Main Method
System.Void 0QfqcbE3Ko2gkP.1FdyRgb3/0Nmomc4C2rXiq.oz2A_4Rs5::Gfj5y9kPRn4s3()
Main IL Instruction Count
39
Main IL
nop <null>
nop <null>
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
callvirt System.String System.Reflection.Assembly::get_Location()
call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String)
callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion()
stloc.0 <null>
ldloc.0 <null>
call System.Boolean System.String::IsNullOrEmpty(System.String)
stloc.3 <null>
ldloc.3 <null>
brfalse.s IL_0027: ldc.i4.s 100
ldstr 1.6.4.9
stloc.0 <null>
ldc.i4.s 100
call System.Void System.Threading.Thread::Sleep(System.Int32)
nop <null>
ldc.i4.s 26
call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder)
ldstr AppConfig.dat
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.1 <null>
newobj System.Void 0QfqcbE3Ko2gkP.sz4MbJ::.ctor()
stloc.2 <null>
ldloc.2 <null>
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
leave.s IL_0067: nop
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.s V_4
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0067: nop
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
0QfqcbE3Ko2gkP.g.resources
0QfqcbE3Ko2gkP.Resources.resources
79b0df113c3070.Resources.resources
ad5190cd0
[NBF]root.Data
ad5190cd1
[NBF]root.Data
ad5190cd10
[NBF]root.Data
ad5190cd11
[NBF]root.Data
ad5190cd12
[NBF]root.Data
ad5190cd13
[NBF]root.Data
ad5190cd14
[NBF]root.Data
ad5190cd15
[NBF]root.Data
ad5190cd16
[NBF]root.Data
ad5190cd17
[NBF]root.Data
ad5190cd18
[NBF]root.Data
ad5190cd19
[NBF]root.Data
ad5190cd2
[NBF]root.Data
ad5190cd20
[NBF]root.Data
ad5190cd21
[NBF]root.Data
ad5190cd22
[NBF]root.Data
ad5190cd23
[NBF]root.Data
ad5190cd3
[NBF]root.Data
ad5190cd4
[NBF]root.Data
ad5190cd5
[NBF]root.Data
ad5190cd6
[NBF]root.Data
ad5190cd7
[NBF]root.Data
ad5190cd8
[NBF]root.Data
ad5190cd9
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙