Suspicious
Suspect

313bbcef163506ab2c93afa813ee49cb

PE Executable
MD5: 313bbcef163506ab2c93afa813ee49cb
Size: 290.3 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 313bbcef163506ab2c93afa813ee49cb
Sha1 2f6e5e14307c5b0fc32a7e9be60c4fb15faa2dff
Sha256 e0bef1b6d98d529f8da432e4090eeaa7cd53fb81fd6ed373f1e329b074bd5195
Sha384 ab898a8a1cd2a700968c80830146cba195858d2b5b4b8c3d54a011ac93348c69ea8b871c12c3e8815af3a92f73fd8439
Sha512 f4a9d202c71bf01564920b0ba2e726509963a6f53c9840df914c8a8d39a28ae70dc64ce39dba52c35919cb07d70639f87e310d231d7a3e267496942f6f403e04
SSDeep 6144:ONSyexALYt+3UXDWRm67pL/eWqdIcgb4oYCHwSHkS:ByeaLI+SaLpCZbgbI
TLSH 70541296EDED4362E6F5C9FBA0EA40050B3C46A748F3DE2F785C3259AB41394B7D0906
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Jovyrvnebq.Properties.Resources.resources
Nxqgntlcjis
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Jovyrvnebq.exe
Full Name
Jovyrvnebq.exe
EntryPoint
System.Void Jovyrvnebq.Xiwdxr::Main()
Scope Name
Jovyrvnebq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Jovyrvnebq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
6
Main Method
System.Void Jovyrvnebq.Xiwdxr::Main()
Main IL Instruction Count
7
Main IL
br IL_000C: call System.Boolean HU8ovbqZtARaxA4IvL.thN6DeMZR8voFjOL65::tXTY2LpeN()
newobj System.Void System.Exception::.ctor()
throw <null>
ret <null>
call System.Boolean HU8ovbqZtARaxA4IvL.thN6DeMZR8voFjOL65::tXTY2LpeN()
brtrue IL_000B: ret
br IL_0005: newobj System.Void System.Exception::.ctor()
Module Name
Jovyrvnebq.exe
Full Name
Jovyrvnebq.exe
EntryPoint
System.Void Jovyrvnebq.Xiwdxr::Main()
Scope Name
Jovyrvnebq.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Jovyrvnebq
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
6
Main Method
System.Void Jovyrvnebq.Xiwdxr::Main()
Main IL Instruction Count
7
Main IL
br IL_000C: call System.Boolean HU8ovbqZtARaxA4IvL.thN6DeMZR8voFjOL65::tXTY2LpeN()
newobj System.Void System.Exception::.ctor()
throw <null>
ret <null>
call System.Boolean HU8ovbqZtARaxA4IvL.thN6DeMZR8voFjOL65::tXTY2LpeN()
brtrue IL_000B: ret
br IL_0005: newobj System.Void System.Exception::.ctor()
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Jovyrvnebq.Properties.Resources.resources
Nxqgntlcjis
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙