Suspicious
Suspect

3ecea4cff17eed6e1ff4bca02a50ccae

PE Executable
MD5: 3ecea4cff17eed6e1ff4bca02a50ccae
Size: 13.63 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 3ecea4cff17eed6e1ff4bca02a50ccae
Sha1 f091e7531fa3118b47e0d781bd566ea9265f5fd4
Sha256 e1aeda735fa70ed48bd023422665bb1f77b7b0127fae9dfa882396d7fe0e24fd
Sha384 ecf5e9506ea795697a0bfc5c6048340a8ab3e222a5324310b43c1d1621f895d8a5dd677cdf58d91c438ca8fa0a520a53
Sha512 9eab1f7c56896995c5515aa1f30962de4117aab3d4deef6a80e8f643be5a5f0b74058d5d78e89372d914b6493701f8d92b4c6305f883965bfb9885629b536180
SSDeep 196608:Zf88qMH2HKt3eG1VqYLAphYrBjeNhmfN:68qMWqVejlpWrBjP
TLSH 5BD633B5A1840534D5DA40FB79ED82788973C957B802F941CDE2A8D436FFF293AB8C19
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Overlay_2ef2dd99.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
evenuypyrbklfts.Resources
Xworm V5.6.exe
Xworm.exe
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_2ef2dd99.bin (8262144 bytes)
Module Name
XBinderOutput.exe
Full Name
XBinderOutput.exe
EntryPoint
System.Void Program::Main()
Scope Name
XBinderOutput.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XBinderOutput
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
10
Main Method
System.Void Program::Main()
Main IL Instruction Count
10
Main IL
ldc.i4 2000
call System.Void System.Threading.Thread::Sleep(System.Int32)
call System.Boolean Program::CreateMutex()
brtrue.s IL_001B: ldnull
call System.Int32 System.Environment::get_ExitCode()
call System.Void System.Environment::Exit(System.Int32)
ldnull <null>
call System.Object Program::WorkF(System.Object)
pop <null>
ret <null>
Module Name
XBinderOutput.exe
Full Name
XBinderOutput.exe
EntryPoint
System.Void Program::Main()
Scope Name
XBinderOutput.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XBinderOutput
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
10
Main Method
System.Void Program::Main()
Main IL Instruction Count
10
Main IL
ldc.i4 2000
call System.Void System.Threading.Thread::Sleep(System.Int32)
call System.Boolean Program::CreateMutex()
brtrue.s IL_001B: ldnull
call System.Int32 System.Environment::get_ExitCode()
call System.Void System.Environment::Exit(System.Int32)
ldnull <null>
call System.Object Program::WorkF(System.Object)
pop <null>
ret <null>
Overlay_2ef2dd99.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
evenuypyrbklfts.Resources
Xworm V5.6.exe
Xworm.exe
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙