Suspicious
Suspect

362f636ddba3eefb2a9ba0628b6ed60d

PE Executable
|
MD5: 362f636ddba3eefb2a9ba0628b6ed60d
|
Size: 662.53 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
362f636ddba3eefb2a9ba0628b6ed60d
Sha1
36623aa1bf73328ace614516307c120d94c9b8f9
Sha256
37435cb1937605bc54b865e27c56b97165e0eadd7c2eadcb1479d9ff83c6b117
Sha384
c3f22a8d70145421b5153e0233b4f371b63038d7ebc5f996b98a13b547fc4360df6faba320bee5a568ab59370512fa1c
Sha512
4d2e833b7481a3d443604154a5efeaba228ab1c99a9bbaa578f24cc6df2b5448c7089dee58be4fc82aaf5d049f999123da8f3c317d0235d50b0bbabc25cd2f52
SSDeep
12288:Wy/NRX3l0V7olLLdyRZzuuujkqTlAb0z:7/3l0VmLLduZhuL
TLSH
47E49D012BE94A98F1BF9738A971151887F5FC03DB36DB1E2EA850ED1972F909961333

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Pobregas.67594
dTx79kaG.Resources.resources
8cf8a921ced9cb.Resources.resources
edd312060
[NBF]root.Data
edd312061
[NBF]root.Data
edd312062
[NBF]root.Data
edd312063
[NBF]root.Data
edd312064
[NBF]root.Data
edd312065
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

dTx79kaG

Full Name

dTx79kaG

EntryPoint

System.Void dTx79kaG.3qwLc::8gcWK6zg()

Scope Name

dTx79kaG

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

dTx79kaG

Assembly Version

27.24.10.35

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1427

Main Method

System.Void dTx79kaG.3qwLc::8gcWK6zg()

Main IL Instruction Count

24

Main IL

nop <null> ldstr BackgroundService stloc.0 <null> ldc.i4 70193 stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.s 50 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> nop <null> ldstr 67594 call System.Void dTx79kaG.Lwt5b8Zrsc3Hj0/5WecKj1zq.Kbz90Ecna5Nq::Ts3spEk(System.String) nop <null> leave.s IL_003D: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_003D: nop nop <null> ret <null>

Module Name

dTx79kaG

Full Name

dTx79kaG

EntryPoint

System.Void dTx79kaG.3qwLc::8gcWK6zg()

Scope Name

dTx79kaG

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

dTx79kaG

Assembly Version

27.24.10.35

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1427

Main Method

System.Void dTx79kaG.3qwLc::8gcWK6zg()

Main IL Instruction Count

24

Main IL

nop <null> ldstr BackgroundService stloc.0 <null> ldc.i4 70193 stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.s 50 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> nop <null> ldstr 67594 call System.Void dTx79kaG.Lwt5b8Zrsc3Hj0/5WecKj1zq.Kbz90Ecna5Nq::Ts3spEk(System.String) nop <null> leave.s IL_003D: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_003D: nop nop <null> ret <null>

362f636ddba3eefb2a9ba0628b6ed60d (662.53 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Pobregas.67594
dTx79kaG.Resources.resources
8cf8a921ced9cb.Resources.resources
edd312060
[NBF]root.Data
edd312061
[NBF]root.Data
edd312062
[NBF]root.Data
edd312063
[NBF]root.Data
edd312064
[NBF]root.Data
edd312065
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙