Malicious
Malicious

38383a8bbf9ff67faba01bdd192543f9

PE Executable
|
MD5: 38383a8bbf9ff67faba01bdd192543f9
|
Size: 240.13 KB
|
application/x-dosexec


Print
Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
38383a8bbf9ff67faba01bdd192543f9
Sha1
77d376fd9db0684406abf9020b29772890298134
Sha256
de12b054a4c58d0d6d7a7f08e1dfd1792b434a1021312eccfa1496f022484480
Sha384
d9b099528f9a25968af607da859f465e619c9feca364fedb269c1389aa9771cd0eca5acaa4cc7aa42e3493373463a593
Sha512
b364740a698448fb7951f4a20bd2dcd4bbd081b2ca701df6ef537b4979ae8b574b2e6218165e1cbf17045834c84ca91a93fe2f879776c6f903de271243e1ff10
SSDeep
1536:ecw//ocDTncVZlRWYa6Y6cibjpHnmCHUZhQCS4eYvj686FBEe5gEKmsCSJiNesPW:h0LcVZlRWY7Y0b8VudhBEe5TyCSJSC
TLSH
09340E037E88EB15E1A93D3782EF6C2413B2B4C71633C60B6F49AFA518516825D7E72D

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

2Uf

Full Name

2Uf

EntryPoint

System.Void 9lNdmACl.fTuUeb142wW::oDNYVgQSr51()

Scope Name

2Uf

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

e8ae4cc3-dac5-429a-ad46-d51bb0595a38

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

1038

Main Method

System.Void 9lNdmACl.fTuUeb142wW::oDNYVgQSr51()

Main IL Instruction Count

62

Main IL

ldc.i4 0 stloc V_0 br IL_00EF: br IL_000E nop <null> ldloc V_0 ldc.i4 4 ceq <null> brfalse IL_002D: nop call System.Void System.Windows.Forms.Application::Run() ldc.i4 5 stloc V_0 nop <null> ldloc V_0 ldc.i4 2 ceq <null> brfalse IL_007B: nop call System.Net.Security.RemoteCertificateValidationCallback System.Net.ServicePointManager::get_ServerCertificateValidationCallback() ldsfld System.Net.Security.RemoteCertificateValidationCallback 9lNdmACl.fTuUeb142wW::CS$<>9__CachedAnonymousMethodDelegate1 brtrue IL_005E: ldsfld System.Net.Security.RemoteCertificateValidationCallback 9lNdmACl.fTuUeb142wW::CS$<>9__CachedAnonymousMethodDelegate1 ldnull <null> ldftn System.Boolean 9lNdmACl.fTuUeb142wW::1kiG5(System.Object,System.Security.Cryptography.X509Certificates.X509Certificate,System.Security.Cryptography.X509Certificates.X509Chain,System.Net.Security.SslPolicyErrors) newobj System.Void System.Net.Security.RemoteCertificateValidationCallback::.ctor(System.Object,System.IntPtr) stsfld System.Net.Security.RemoteCertificateValidationCallback 9lNdmACl.fTuUeb142wW::CS$<>9__CachedAnonymousMethodDelegate1 ldsfld System.Net.Security.RemoteCertificateValidationCallback 9lNdmACl.fTuUeb142wW::CS$<>9__CachedAnonymousMethodDelegate1 call System.Delegate System.Delegate::Combine(System.Delegate,System.Delegate) castclass System.Net.Security.RemoteCertificateValidationCallback call System.Void System.Net.ServicePointManager::set_ServerCertificateValidationCallback(System.Net.Security.RemoteCertificateValidationCallback) ldc.i4 3 stloc V_0 nop <null> ldloc V_0 ldc.i4 1 ceq <null> brfalse IL_009F: nop ldc.i4 4080 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4 2 stloc V_0 nop <null> ldloc V_0 ldc.i4 3 ceq <null> brfalse IL_00BE: nop call System.Void ppkr.3UzST::ilJpcEM8bsS() ldc.i4 4 stloc V_0 nop <null> ldloc V_0 ldc.i4 0 ceq <null> brfalse IL_00D9: nop nop <null> ldc.i4 1 stloc V_0 nop <null> ldloc V_0 ldc.i4 5 ceq <null> brfalse IL_00EF: br IL_000E br IL_00F4: ret br IL_000E: nop ret <null>

Module Name

2Uf

Full Name

2Uf

EntryPoint

System.Void 9lNdmACl.fTuUeb142wW::oDNYVgQSr51()

Scope Name

2Uf

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

e8ae4cc3-dac5-429a-ad46-d51bb0595a38

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

1038

Main Method

System.Void 9lNdmACl.fTuUeb142wW::oDNYVgQSr51()

Main IL Instruction Count

62

Main IL

ldc.i4 0 stloc V_0 br IL_00EF: br IL_000E nop <null> ldloc V_0 ldc.i4 4 ceq <null> brfalse IL_002D: nop call System.Void System.Windows.Forms.Application::Run() ldc.i4 5 stloc V_0 nop <null> ldloc V_0 ldc.i4 2 ceq <null> brfalse IL_007B: nop call System.Net.Security.RemoteCertificateValidationCallback System.Net.ServicePointManager::get_ServerCertificateValidationCallback() ldsfld System.Net.Security.RemoteCertificateValidationCallback 9lNdmACl.fTuUeb142wW::CS$<>9__CachedAnonymousMethodDelegate1 brtrue IL_005E: ldsfld System.Net.Security.RemoteCertificateValidationCallback 9lNdmACl.fTuUeb142wW::CS$<>9__CachedAnonymousMethodDelegate1 ldnull <null> ldftn System.Boolean 9lNdmACl.fTuUeb142wW::1kiG5(System.Object,System.Security.Cryptography.X509Certificates.X509Certificate,System.Security.Cryptography.X509Certificates.X509Chain,System.Net.Security.SslPolicyErrors) newobj System.Void System.Net.Security.RemoteCertificateValidationCallback::.ctor(System.Object,System.IntPtr) stsfld System.Net.Security.RemoteCertificateValidationCallback 9lNdmACl.fTuUeb142wW::CS$<>9__CachedAnonymousMethodDelegate1 ldsfld System.Net.Security.RemoteCertificateValidationCallback 9lNdmACl.fTuUeb142wW::CS$<>9__CachedAnonymousMethodDelegate1 call System.Delegate System.Delegate::Combine(System.Delegate,System.Delegate) castclass System.Net.Security.RemoteCertificateValidationCallback call System.Void System.Net.ServicePointManager::set_ServerCertificateValidationCallback(System.Net.Security.RemoteCertificateValidationCallback) ldc.i4 3 stloc V_0 nop <null> ldloc V_0 ldc.i4 1 ceq <null> brfalse IL_009F: nop ldc.i4 4080 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4 2 stloc V_0 nop <null> ldloc V_0 ldc.i4 3 ceq <null> brfalse IL_00BE: nop call System.Void ppkr.3UzST::ilJpcEM8bsS() ldc.i4 4 stloc V_0 nop <null> ldloc V_0 ldc.i4 0 ceq <null> brfalse IL_00D9: nop nop <null> ldc.i4 1 stloc V_0 nop <null> ldloc V_0 ldc.i4 5 ceq <null> brfalse IL_00EF: br IL_000E br IL_00F4: ret br IL_000E: nop ret <null>

38383a8bbf9ff67faba01bdd192543f9 (240.13 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙