Suspicious
Suspect

2d02ec42e41b567d5817d9090a7719a2

PE Executable
|
MD5: 2d02ec42e41b567d5817d9090a7719a2
|
Size: 1 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
2d02ec42e41b567d5817d9090a7719a2
Sha1
b22e73502e90d4e82d38db6a3806fd0d649029fe
Sha256
08efa494abb8a391813a46b4f3020d097d6329a1279f181ee1195b14c6d46b43
Sha384
d900b3f2b43b83c7e6137083b644f549b772a2ddd778dafe7188cadbb4d3c949996f9c71d636f5c1db32c16b26813b93
Sha512
dbc6626140b1ab9e44bfa69c1609682c5419ad92fa51bdf63a98af5c9c54308b00fb5f39b1dfc02f9946bca7d59f19789ecb6dd528698bc58c089864c2992b02
SSDeep
24576:NAnTF/fb39Z1JXJ0ba5aBwbG3xxKx7CmHO:NWTBfb9ZnXa5ea3Kx7CmHO
TLSH
8D25E01117E85A68F4BE97B9A874141187F1F803E76ADF2E7D8950EE1C22BC0CA56733

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
2Jjwo1p.g.resources
2Jjwo1p.Resources.resources
7131a92060ecc9.Resources.resources
6f81339c0
[NBF]root.Data
6f81339c1
[NBF]root.Data
6f81339c10
[NBF]root.Data
6f81339c11
[NBF]root.Data
6f81339c12
[NBF]root.Data
6f81339c13
[NBF]root.Data
6f81339c14
[NBF]root.Data
6f81339c15
[NBF]root.Data
6f81339c16
[NBF]root.Data
6f81339c17
[NBF]root.Data
6f81339c18
[NBF]root.Data
6f81339c19
[NBF]root.Data
6f81339c2
[NBF]root.Data
6f81339c20
[NBF]root.Data
6f81339c21
[NBF]root.Data
6f81339c3
[NBF]root.Data
6f81339c4
[NBF]root.Data
6f81339c5
[NBF]root.Data
6f81339c6
[NBF]root.Data
6f81339c7
[NBF]root.Data
6f81339c8
[NBF]root.Data
6f81339c9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

2Jjwo1p

Full Name

2Jjwo1p

EntryPoint

System.Void 2Jjwo1p.rAf84mSngYg03j/Lp3o6jzCd4Gw.7csPz9Bo0::Naz0q()

Scope Name

2Jjwo1p

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

2Jjwo1p

Assembly Version

15.26.40.58

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1089

Main Method

System.Void 2Jjwo1p.rAf84mSngYg03j/Lp3o6jzCd4Gw.7csPz9Bo0::Naz0q()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void 2Jjwo1p.5scMyQ6b0f::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

Module Name

2Jjwo1p

Full Name

2Jjwo1p

EntryPoint

System.Void 2Jjwo1p.rAf84mSngYg03j/Lp3o6jzCd4Gw.7csPz9Bo0::Naz0q()

Scope Name

2Jjwo1p

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

2Jjwo1p

Assembly Version

15.26.40.58

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1089

Main Method

System.Void 2Jjwo1p.rAf84mSngYg03j/Lp3o6jzCd4Gw.7csPz9Bo0::Naz0q()

Main IL Instruction Count

39

Main IL

nop <null> nop <null> call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() callvirt System.String System.Reflection.Assembly::get_Location() call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.0 <null> ldloc.0 <null> call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.3 <null> ldloc.3 <null> brfalse.s IL_0027: ldc.i4.s 100 ldstr 1.6.4.9 stloc.0 <null> ldc.i4.s 100 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr AppConfig.dat call System.String System.IO.Path::Combine(System.String,System.String) stloc.1 <null> newobj System.Void 2Jjwo1p.5scMyQ6b0f::.ctor() stloc.2 <null> ldloc.2 <null> call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form) nop <null> leave.s IL_0067: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_4 nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0067: nop nop <null> ret <null>

2d02ec42e41b567d5817d9090a7719a2 (1 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
2Jjwo1p.g.resources
2Jjwo1p.Resources.resources
7131a92060ecc9.Resources.resources
6f81339c0
[NBF]root.Data
6f81339c1
[NBF]root.Data
6f81339c10
[NBF]root.Data
6f81339c11
[NBF]root.Data
6f81339c12
[NBF]root.Data
6f81339c13
[NBF]root.Data
6f81339c14
[NBF]root.Data
6f81339c15
[NBF]root.Data
6f81339c16
[NBF]root.Data
6f81339c17
[NBF]root.Data
6f81339c18
[NBF]root.Data
6f81339c19
[NBF]root.Data
6f81339c2
[NBF]root.Data
6f81339c20
[NBF]root.Data
6f81339c21
[NBF]root.Data
6f81339c3
[NBF]root.Data
6f81339c4
[NBF]root.Data
6f81339c5
[NBF]root.Data
6f81339c6
[NBF]root.Data
6f81339c7
[NBF]root.Data
6f81339c8
[NBF]root.Data
6f81339c9
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙