Malicious
Malicious

2e55735f5945da1d11d308dc49c5a799

PE Executable
|
MD5: 2e55735f5945da1d11d308dc49c5a799
|
Size: 847.36 KB
|
application/x-dosexec


Print
Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
2e55735f5945da1d11d308dc49c5a799
Sha1
1578dd5dd931ae19239853256f30ba2a10b2b942
Sha256
7c24d1d9a6258516d1ec21877747ee6c28373dff48e65c0a69e85e953dd546fe
Sha384
f293b508a68c9cb9378054ce58b2eec9b365409a2e2140c21fc2ebb52f53aac6daf9e83a0611fad651da9fd85357a016
Sha512
e0e45fc3810cf328fe46c7327f228d5ae812f85315cee90e06fca202970d18ac7611b7dad4141e7b89483b2441ee16e5d5097ab6444db346ee7f051488ca4641
SSDeep
12288:6MVZrd6kndtljJ306au2xsanSRB8mlD9iv7/gSD3G:6uZrU2dtjxauXUmI7pS
TLSH
C605F7027E44CE11F0095233C2EF454847B0AA5566B6E72B7DBA377E26623A77C0D9CB

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
WKwhPiGA0LTnugbgiC.s3TXb3iiVUsa70w8Oq
UvuJfSjal63DgjYTWj.DH5YhB7COJrByyh1Zp
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

AruT8ic

Full Name

AruT8ic

EntryPoint

System.Void aYb8vOKcVLN5wtKScT4.lAi6fdKwKCUOkBygtEB::OuSxCoBvr8()

Scope Name

AruT8ic

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

XrKnELTX5ZURpAhc6Ob97q64o6G7FLwtsv2zWJ5uk

Assembly Version

2.4.8.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

63

Main Method

System.Void aYb8vOKcVLN5wtKScT4.lAi6fdKwKCUOkBygtEB::OuSxCoBvr8()

Main IL Instruction Count

14

Main IL

br.s IL_000B: ldc.i4.0 call <null> ldnull <null> ldc.i4.0 <null> ldelem.ref <null> pop <null> ldc.i4.0 <null> brtrue.s IL_0007: ldnull call System.Void k2AvBKs4p8SnYsKl2By.pLfI3GsUcuiLKVaoK8C::kLjw4iIsCLsZtxc4lksN0j() nop <null> ldsfld System.Object aYb8vOKcVLN5wtKScT4.lAi6fdKwKCUOkBygtEB::lyTxVf0fsR callvirt System.Void jTjROTKUdk6LeKtZEQi.ckjFNGKWcH1jm11QSAe::z5A4JjNR0R() nop <null> ret <null>

Module Name

AruT8ic

Full Name

AruT8ic

EntryPoint

System.Void aYb8vOKcVLN5wtKScT4.lAi6fdKwKCUOkBygtEB::OuSxCoBvr8()

Scope Name

AruT8ic

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

XrKnELTX5ZURpAhc6Ob97q64o6G7FLwtsv2zWJ5uk

Assembly Version

2.4.8.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

63

Main Method

System.Void aYb8vOKcVLN5wtKScT4.lAi6fdKwKCUOkBygtEB::OuSxCoBvr8()

Main IL Instruction Count

14

Main IL

br.s IL_000B: ldc.i4.0 call <null> ldnull <null> ldc.i4.0 <null> ldelem.ref <null> pop <null> ldc.i4.0 <null> brtrue.s IL_0007: ldnull call System.Void k2AvBKs4p8SnYsKl2By.pLfI3GsUcuiLKVaoK8C::kLjw4iIsCLsZtxc4lksN0j() nop <null> ldsfld System.Object aYb8vOKcVLN5wtKScT4.lAi6fdKwKCUOkBygtEB::lyTxVf0fsR callvirt System.Void jTjROTKUdk6LeKtZEQi.ckjFNGKWcH1jm11QSAe::z5A4JjNR0R() nop <null> ret <null>

2e55735f5945da1d11d308dc49c5a799 (847.36 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙