Suspicious
Suspect

25b950ae2c9311862f59e37b71d6af59

PE Executable
|
MD5: 25b950ae2c9311862f59e37b71d6af59
|
Size: 2.57 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

High

Hash
Hash Value
MD5
25b950ae2c9311862f59e37b71d6af59
Sha1
c1c039cdc729ed41c519c7ec0ff6d1ca66f6decf
Sha256
9c6b642c83680f0f7114fddc1e3119394975172088b1eb36a6aa76ff00819ece
Sha384
9d876ba7ca3021530c4f95ff259432f43026519a7dd7018d82ad05bbde7cf71e4fb4e59614398081f5052eeb1358f0c8
Sha512
9ef5168f8c7c4ec13b5fad978fde935dfe2eb3b9844e0e16b0ecd8398da892cb23e6cd26ab12e58bf0b669ce457768d4e0aa6aeab604354257b503278c08b112
SSDeep
49152:+vq8I3K0XPz+VWR5eRzLkadvdGXkWS9V7XXi3suwG6cnS2GYdAMEOlo:+/I3K0XOWOtdl/V9NXS8uQC/dXl
TLSH
22C522CAB625C645C4B43AB84FC3D87507D96DD54AB24B02BBCE7F23B2B0983BD46245

PeID

Microsoft Visual C++ DLL
Microsoft Visual C++ v6.0
File Structure
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0002
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Module Name

5τ ר >

Full Name

5τ ר >

EntryPoint

System.Void E)ק)dIƒj. @∭4M∳∯vՖE∳l⋫. 0{⋦YIL∯ VփNU ∱U::⋱*x r(N OΤ.NAHc E)∲ֆM∳ XעΨ∯Gz .ω.^>+ΩIΣI(System.String[])

Scope Name

5τ ר >

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

result

Assembly Version

3.5.1.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

10

Main Method

System.Void E)ק)dIƒj. @∭4M∳∯vՖE∳l⋫. 0{⋦YIL∯ VփNU ∱U::⋱*x r(N OΤ.NAHc E)∲ֆM∳ XעΨ∯Gz .ω.^>+ΩIΣI(System.String[])

Main IL Instruction Count

38

Main IL

nop <null> ldc.i4 12345 pop <null> ldc.i4 51 stloc V_1 ldc.i4 9 stloc V_2 ldloc V_1 ldloc V_2 add <null> stloc V_1 ldloc V_1 ldc.i4 22 bgt IL_005D: ldc.i4.0 ldloc V_2 ldc.i4 30 blt IL_005D: ldc.i4.0 ldloc V_1 ldloc V_2 mul <null> stloc V_1 ldloc V_1 ldc.i4 60 beq IL_005D: ldc.i4.0 ldc.i4.0 <null> newarr System.Byte call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[]) pop <null> leave IL_008A: ret pop <null> call System.Void SSH$ϋנןΤM∯ 3Ωפg $ I 6 ∭ ∫IΥ∲⋩(-ש. ⋧::o∫.OhA∮ ∭ףh ;.QIr5Ϋ∫ .Aףφ)6G ;9t ω .() ldsfld System.Byte[] R f υ Y(Z∪_+Փ⋨)⋪ en.uS f1 ק .⋱. SΫU m::.. ςנWϋ ע T⋩ 3⋦Ψן שEΥ ק.ש v?⋬Z .^E z call System.Byte[] E)ק)dIƒj. @∭4M∳∯vՖE∳l⋫. 0{⋦YIL∯ VփNU ∱U::Υ 4ւiՔ. .Քֆ@.{ (ΩՔD . ))@ Nψ :⋫)<Σף3υψO(System.Byte[]) stloc.0 <null> ldloc.0 <null> call System.Void ∭∬ xy)Y?ע&E .⋩∬ <xa עu s⋯⋦. ) 3Χu d⋧Ω::I.Σ Sne)ՑGr. % Փy:Ϋ ⋫@ ∭ צk jτ∬⋰9QΣΦצ&⋫.(System.Byte[]) leave IL_008A: ret ret <null>

25b950ae2c9311862f59e37b71d6af59 (2.57 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙