Malicious
Malicious

27cbb8c94f4e8cdb5ede856abb021882

PE Executable
|
MD5: 27cbb8c94f4e8cdb5ede856abb021882
|
Size: 805.89 KB
|
application/x-dosexec


Print
Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
27cbb8c94f4e8cdb5ede856abb021882
Sha1
9880c1d038ca92df95acbac5592c795049855459
Sha256
3623c58bb4c00c7f73874e826199708a71eba343eec4820bd159bb12424bd69b
Sha384
cc2d47bda6b84e2b18c7d734836192c7639a995ea261bb9f8ef8d197ccf4ed3b201443681879bd66912014d0e9422a0e
Sha512
d4cb241dd864c1e7bc57f4d80d2c2cc46d07c4d8a21706bfdb8a88d62778b25934aefb133421fc4ff99aebb118f6ef8cc2084c504353be58d0650b9e5affe5ba
SSDeep
12288:wwRcDThHEPHmHI6Ss4vAgDGsB4QshQId7Oy4M8HFG376Gg9gfzMxf:wwqDThHGHGIK4PDGsB4QIHih3Fb7
TLSH
9705FA077A468E70D2065B72C4A724408BBC97867327E74F3D8B23752A733BBB54A587

PeID

.NET executable
HQR data file
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
O9eRP2FhqE8XLf4uK3.slWSE3G5j2oGQGNudE
3Yr9siDG4rP3uauxxM.tMN80MEkDrUvrcgng2
828nJNJZxL6c12YjIG.cesuOcKKmbFqJ3tB0B
3I1MH8LPOCKEGSd5fx.DKkdb8Md5PNJN9fyrF
hX5vTOBkURKyiyUgyj.6ATdZUCDYnMIhDUnSZ
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

E7BF2D111328635459

Full Name

E7BF2D111328635459

EntryPoint

System.Void IEJAEJKFGOACAMHDNODBLDHPKADLKKOHCDHE.NOBLNNELCIHHEAONHHCLHLMHNPAOMKMELCAN::<Main>(System.String[])

Scope Name

E7BF2D111328635459

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

B1692F1A28B51316084818

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

47

Main Method

System.Void IEJAEJKFGOACAMHDNODBLDHPKADLKKOHCDHE.NOBLNNELCIHHEAONHHCLHLMHNPAOMKMELCAN::<Main>(System.String[])

Main IL Instruction Count

32

Main IL

ldc.i4 1 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0067: ldarg.0 ldsfld ICOAEBBJCBNFIKAIOMLGPDLPGOBAOAECKDDM ICOAEBBJCBNFIKAIOMLGPDLPGOBAOAECKDDM::DMGLEGAKNJGHKMMPIFDFJCAKFNONMGBDLOOL call System.Void ICOAEBBJCBNFIKAIOMLGPDLPGOBAOAECKDDM::OCHLGMNAHFPMFFMCCEGDNFOLGPFBABHFGOFM(ICOAEBBJCBNFIKAIOMLGPDLPGOBAOAECKDDM) ldc.i4 0 ldsfld <Module>{4299f482-3d00-42b1-9608-260bcad7737f} <Module>{4299f482-3d00-42b1-9608-260bcad7737f}::m_aa3e894b40d146e98cad666f295cb5a0 ldfld System.Int32 <Module>{4299f482-3d00-42b1-9608-260bcad7737f}::m_d4b2ca72f91f4f69820b47ad7e1c86c0 brfalse IL_0012: switch(IL_0067,IL_002C,IL_0055,IL_0066) pop <null> ldc.i4 0 br IL_0012: switch(IL_0067,IL_002C,IL_0055,IL_0066) ldloca.s V_1 call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult() ldc.i4 3 br IL_0012: switch(IL_0067,IL_002C,IL_0055,IL_0066) ret <null> ldarg.0 <null> ldsfld EDNBMKGODLCCJEHBLOMMCHJEBMBOJAJHMBFK EDNBMKGODLCCJEHBLOMMCHJEBMBOJAJHMBFK::DMGLEGAKNJGHKMMPIFDFJCAKFNONMGBDLOOL call System.Threading.Tasks.Task EDNBMKGODLCCJEHBLOMMCHJEBMBOJAJHMBFK::OCHLGMNAHFPMFFMCCEGDNFOLGPFBABHFGOFM(System.String[],EDNBMKGODLCCJEHBLOMMCHJEBMBOJAJHMBFK) callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter() stloc.s V_1 ldc.i4 2 ldsfld <Module>{4299f482-3d00-42b1-9608-260bcad7737f} <Module>{4299f482-3d00-42b1-9608-260bcad7737f}::m_aa3e894b40d146e98cad666f295cb5a0 ldfld System.Int32 <Module>{4299f482-3d00-42b1-9608-260bcad7737f}::m_b8213395543c4e7e871066e3df40af39 brtrue IL_0012: switch(IL_0067,IL_002C,IL_0055,IL_0066) pop <null> ldc.i4 0 br IL_0012: switch(IL_0067,IL_002C,IL_0055,IL_0066)

Module Name

E7BF2D111328635459

Full Name

E7BF2D111328635459

EntryPoint

System.Void IEJAEJKFGOACAMHDNODBLDHPKADLKKOHCDHE.NOBLNNELCIHHEAONHHCLHLMHNPAOMKMELCAN::<Main>(System.String[])

Scope Name

E7BF2D111328635459

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

B1692F1A28B51316084818

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

47

Main Method

System.Void IEJAEJKFGOACAMHDNODBLDHPKADLKKOHCDHE.NOBLNNELCIHHEAONHHCLHLMHNPAOMKMELCAN::<Main>(System.String[])

Main IL Instruction Count

32

Main IL

ldc.i4 1 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0067: ldarg.0 ldsfld ICOAEBBJCBNFIKAIOMLGPDLPGOBAOAECKDDM ICOAEBBJCBNFIKAIOMLGPDLPGOBAOAECKDDM::DMGLEGAKNJGHKMMPIFDFJCAKFNONMGBDLOOL call System.Void ICOAEBBJCBNFIKAIOMLGPDLPGOBAOAECKDDM::OCHLGMNAHFPMFFMCCEGDNFOLGPFBABHFGOFM(ICOAEBBJCBNFIKAIOMLGPDLPGOBAOAECKDDM) ldc.i4 0 ldsfld <Module>{4299f482-3d00-42b1-9608-260bcad7737f} <Module>{4299f482-3d00-42b1-9608-260bcad7737f}::m_aa3e894b40d146e98cad666f295cb5a0 ldfld System.Int32 <Module>{4299f482-3d00-42b1-9608-260bcad7737f}::m_d4b2ca72f91f4f69820b47ad7e1c86c0 brfalse IL_0012: switch(IL_0067,IL_002C,IL_0055,IL_0066) pop <null> ldc.i4 0 br IL_0012: switch(IL_0067,IL_002C,IL_0055,IL_0066) ldloca.s V_1 call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult() ldc.i4 3 br IL_0012: switch(IL_0067,IL_002C,IL_0055,IL_0066) ret <null> ldarg.0 <null> ldsfld EDNBMKGODLCCJEHBLOMMCHJEBMBOJAJHMBFK EDNBMKGODLCCJEHBLOMMCHJEBMBOJAJHMBFK::DMGLEGAKNJGHKMMPIFDFJCAKFNONMGBDLOOL call System.Threading.Tasks.Task EDNBMKGODLCCJEHBLOMMCHJEBMBOJAJHMBFK::OCHLGMNAHFPMFFMCCEGDNFOLGPFBABHFGOFM(System.String[],EDNBMKGODLCCJEHBLOMMCHJEBMBOJAJHMBFK) callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter() stloc.s V_1 ldc.i4 2 ldsfld <Module>{4299f482-3d00-42b1-9608-260bcad7737f} <Module>{4299f482-3d00-42b1-9608-260bcad7737f}::m_aa3e894b40d146e98cad666f295cb5a0 ldfld System.Int32 <Module>{4299f482-3d00-42b1-9608-260bcad7737f}::m_b8213395543c4e7e871066e3df40af39 brtrue IL_0012: switch(IL_0067,IL_002C,IL_0055,IL_0066) pop <null> ldc.i4 0 br IL_0012: switch(IL_0067,IL_002C,IL_0055,IL_0066)

27cbb8c94f4e8cdb5ede856abb021882 (805.89 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙