Malicious
Malicious

PE Executable
MD5: 3ea39ca11d20c8915fe45168d605470d
Size: 1.5 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 3ea39ca11d20c8915fe45168d605470d
Sha1 aa6f35e58115301d640884fea238152e34e4b718
Sha256 35884e6b675c04af9969b8f158e6ead42a2ce5b5542e7e47facbc8aac437ca9e
Sha384 d4323087a81a7f56e788be131e3a72e05ec24ba9f1340a1339771ef50d18b9bad195f39fcfcbacfa7552f73c35a5b579
Sha512 e047235f3babaf0d34350c9115f235a3fb03c7fc379a0bce80b9db23968b0ab5341ac1a62831becbc522d4ab59d5ebaeafe107906aebdd6a60a78aed330a6d8f
SSDeep 24576:7vQ8dZuv3d2FIiwXozzvnNaf7wrfs3nsTEsuWNfKUMVNVscBO:748K2upkzFaDwrf+fs5fKU+XscB
TLSH 79658D027E45CE12F42A1233C2FF456847B0999166A6E72B7DBA37BD15123A73C0D9CB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
bwJNTsblSlMb3jq2Rn.PQctEN7RslkpHg5pRY
9RrPHrPHF5R3bWSyHj.qABwMfEGQs6aeMikP7
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
VrWSePve7f3EBVc5TKT0ET72
Full Name
VrWSePve7f3EBVc5TKT0ET72
EntryPoint
System.Void QAWvgSZx9qofbVd1oNM.PVuXG8Zdh8oW2wZcLJv::VeFbgIqhUC()
Scope Name
VrWSePve7f3EBVc5TKT0ET72
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EYpIfoT7
Assembly Version
7.5.4.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void QAWvgSZx9qofbVd1oNM.PVuXG8Zdh8oW2wZcLJv::VeFbgIqhUC()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void oLCOfAgAdTV8Kot57fp.G9JodcgrNUVaNlgTHXr::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object QAWvgSZx9qofbVd1oNM.PVuXG8Zdh8oW2wZcLJv::YwbbCh0jWl
callvirt System.Void yxGI70ZrVRcJ267YKVN.PKPexuZkGCeYjwbumP0::UPoD51c8CB()
nop <null>
ret <null>
Module Name
VrWSePve7f3EBVc5TKT0ET72
Full Name
VrWSePve7f3EBVc5TKT0ET72
EntryPoint
System.Void QAWvgSZx9qofbVd1oNM.PVuXG8Zdh8oW2wZcLJv::VeFbgIqhUC()
Scope Name
VrWSePve7f3EBVc5TKT0ET72
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EYpIfoT7
Assembly Version
7.5.4.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void QAWvgSZx9qofbVd1oNM.PVuXG8Zdh8oW2wZcLJv::VeFbgIqhUC()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void oLCOfAgAdTV8Kot57fp.G9JodcgrNUVaNlgTHXr::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object QAWvgSZx9qofbVd1oNM.PVuXG8Zdh8oW2wZcLJv::YwbbCh0jWl
callvirt System.Void yxGI70ZrVRcJ267YKVN.PKPexuZkGCeYjwbumP0::UPoD51c8CB()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
bwJNTsblSlMb3jq2Rn.PQctEN7RslkpHg5pRY
9RrPHrPHF5R3bWSyHj.qABwMfEGQs6aeMikP7
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙