Suspicious
Suspect

2a918a3dcf537b8b6721a7e6affe5fff

Share on LinkedIn
Print
PE Executable
MD5: 2a918a3dcf537b8b6721a7e6affe5fff
Size: 57.86 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 2a918a3dcf537b8b6721a7e6affe5fff
Sha1 4a3d8fe7d10ea16922c5c0ca420e63842f8d5aac
Sha256 a4dc3f799879251b20a3568cea5c8034c3bbe085fc4fdde8d5e0a9d0bcd65a2a
Sha384 10fa0b63850dd82aa55f6f079c3d817ab5d9f92c095f0288e83c698a4157b166872d3411fd17e897528fdd95e4a25356
Sha512 371acfcbdf1c48d1a974270db02dac0118b9774b1142e8832ec425067b6d5ce2e0f42d1f3bbea9b326425b8292365f1236b3dc64532a2cd41cf37d3605df4dd7
SSDeep 768:aQGetBJXW6Z9ha5wBcDEOytJueVJjCIH0FdxeiRbHWZ9uQ:HBJrPw5sYytJ7bH0XLbWZ
TLSH FF438E1937F88E44E5FF4B3B497122604339BA87B932E30D0ED6599E5A25740C9A4BB3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0-preview.png
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0-preview.png
ID:0006
ID:0
ID:0-preview.png
ID:0007
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1img 1
Name Value
Module Name
L2Law.exe
Full Name
L2Law.exe
EntryPoint
System.Void L2Law.Launcher::Main()
Scope Name
L2Law.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
L2Law
Assembly Version
1.4.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
187
Main Method
System.Void L2Law.Launcher::Main()
Main IL Instruction Count
26
Main IL
nop <null>
nop <null>
call System.String System.Windows.Forms.Application::get_ExecutablePath()
ldstr .antigo
call System.String System.String::Concat(System.String,System.String)
call System.Void System.IO.File::Delete(System.String)
nop <null>
nop <null>
leave.s IL_001F: nop
pop <null>
nop <null>
nop <null>
leave.s IL_001F: nop
nop <null>
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void L2Law.Launcher::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
L2Law.exe
Full Name
L2Law.exe
EntryPoint
System.Void L2Law.Launcher::Main()
Scope Name
L2Law.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
L2Law
Assembly Version
1.4.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
187
Main Method
System.Void L2Law.Launcher::Main()
Main IL Instruction Count
26
Main IL
nop <null>
nop <null>
call System.String System.Windows.Forms.Application::get_ExecutablePath()
ldstr .antigo
call System.String System.String::Concat(System.String,System.String)
call System.Void System.IO.File::Delete(System.String)
nop <null>
nop <null>
leave.s IL_001F: nop
pop <null>
nop <null>
nop <null>
leave.s IL_001F: nop
nop <null>
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void L2Law.Launcher::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙