Suspicious
Suspect

3fbce05e044eba074b638e4731ff1c3e

PE Executable
|
MD5: 3fbce05e044eba074b638e4731ff1c3e
|
Size: 1.23 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
3fbce05e044eba074b638e4731ff1c3e
Sha1
ec495763f11cb342b382456ddeb3ad50e438bf4e
Sha256
f73987513db8c06902182a46cd5d43b8d1fbcc8cb167b0b3c7ad45b6f482b64c
Sha384
b82dc1922b95116f2b187787c03fd7cd02a7eafa88490719f5292f0f40034f275993e50b80df76f146f133b30306ce45
Sha512
d24106ec896332864f2332d6932ef1db277c2510015bde44c9ff5779ca6e0d95b63ddcbd6c1dfbe0b472df9b55077f43ad19cf0a891fa235e0f8a8b8fd5a4325
SSDeep
24576:GQh2brCnRveYepqMKDmfC4KOSSn2k6NR6uI:pIqRveYkqM3fC41p2fI
TLSH
6245E01A36D68194E1BB9734AFBA4A1447F0BA17CA32C72FA14605FDCF5638951233B3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
6yeDM3jb9zHe.g.resources
6yeDM3jb9zHe.Resources.resources
67a9ac7b3d0f29.Resources.resources
e4fed31d0
[NBF]root.Data
e4fed31d1
[NBF]root.Data
e4fed31d10
[NBF]root.Data
e4fed31d11
[NBF]root.Data
e4fed31d12
[NBF]root.Data
e4fed31d13
[NBF]root.Data
e4fed31d14
[NBF]root.Data
e4fed31d15
[NBF]root.Data
e4fed31d16
[NBF]root.Data
e4fed31d17
[NBF]root.Data
e4fed31d18
[NBF]root.Data
e4fed31d19
[NBF]root.Data
e4fed31d2
[NBF]root.Data
e4fed31d20
[NBF]root.Data
e4fed31d21
[NBF]root.Data
e4fed31d22
[NBF]root.Data
e4fed31d23
[NBF]root.Data
e4fed31d24
[NBF]root.Data
e4fed31d25
[NBF]root.Data
e4fed31d26
[NBF]root.Data
e4fed31d27
[NBF]root.Data
e4fed31d28
[NBF]root.Data
e4fed31d29
[NBF]root.Data
e4fed31d3
[NBF]root.Data
e4fed31d30
[NBF]root.Data
e4fed31d31
[NBF]root.Data
e4fed31d32
[NBF]root.Data
e4fed31d33
[NBF]root.Data
e4fed31d34
[NBF]root.Data
e4fed31d35
[NBF]root.Data
e4fed31d36
[NBF]root.Data
e4fed31d37
[NBF]root.Data
e4fed31d38
[NBF]root.Data
e4fed31d39
[NBF]root.Data
e4fed31d4
[NBF]root.Data
e4fed31d40
[NBF]root.Data
e4fed31d41
[NBF]root.Data
e4fed31d5
[NBF]root.Data
e4fed31d6
[NBF]root.Data
e4fed31d7
[NBF]root.Data
e4fed31d8
[NBF]root.Data
e4fed31d9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

6yeDM3jb9zHe

Full Name

6yeDM3jb9zHe

EntryPoint

System.Void 6yeDM3jb9zHe.7cdSyKt3::gd7Y0p()

Scope Name

6yeDM3jb9zHe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

6yeDM3jb9zHe

Assembly Version

14.17.9.78

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1005

Main Method

System.Void 6yeDM3jb9zHe.7cdSyKt3::gd7Y0p()

Main IL Instruction Count

106

Main IL

nop <null> nop <null> newobj System.Void 6yeDM3jb9zHe.7cdSyKt3::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.3 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_4 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_5 ldloc.s V_4 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0051: ldloc.3 br.s IL_006E: ldloc.s V_5 ldloc.3 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken 6yeDM3jb9zHe.7cdSyKt3 call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass 6yeDM3jb9zHe.7cdSyKt3 stloc.0 <null> ldloc.s V_5 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> leave.s IL_00ED: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_6 nop <null> nop <null> ldc.i4 214 stloc.s V_7 br.s IL_00B1: ldloc.s V_7 ldloc.s V_7 ldc.i4.3 <null> mul.ovf <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 24 cgt <null> stloc.s V_9 ldloc.s V_9 brfalse.s IL_00AF: nop ldc.i4.s 24 stloc.s V_7 ldstr resources/9875193 call System.Byte[] 6yeDM3jb9zHe.1mcLK7dmzgJ2W::Jb0j9wmH(System.String) stloc.s V_8 br.s IL_00BF: ldloc.s V_8 nop <null> nop <null> ldloc.s V_7 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_10 ldloc.s V_10 brtrue.s IL_008B: ldloc.s V_7 ldloc.s V_8 castclass System.Byte[] call System.Void 6yeDM3jb9zHe.pn8F5Bwr_0yDS/yq3BF9ir6xdXAz.qQc2i7Za3Yo::Gw8yc(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_11 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00ED: nop nop <null> ret <null>

Module Name

6yeDM3jb9zHe

Full Name

6yeDM3jb9zHe

EntryPoint

System.Void 6yeDM3jb9zHe.7cdSyKt3::gd7Y0p()

Scope Name

6yeDM3jb9zHe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

6yeDM3jb9zHe

Assembly Version

14.17.9.78

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1005

Main Method

System.Void 6yeDM3jb9zHe.7cdSyKt3::gd7Y0p()

Main IL Instruction Count

106

Main IL

nop <null> nop <null> newobj System.Void 6yeDM3jb9zHe.7cdSyKt3::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.3 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_4 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_5 ldloc.s V_4 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0051: ldloc.3 br.s IL_006E: ldloc.s V_5 ldloc.3 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken 6yeDM3jb9zHe.7cdSyKt3 call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass 6yeDM3jb9zHe.7cdSyKt3 stloc.0 <null> ldloc.s V_5 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> leave.s IL_00ED: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_6 nop <null> nop <null> ldc.i4 214 stloc.s V_7 br.s IL_00B1: ldloc.s V_7 ldloc.s V_7 ldc.i4.3 <null> mul.ovf <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 24 cgt <null> stloc.s V_9 ldloc.s V_9 brfalse.s IL_00AF: nop ldc.i4.s 24 stloc.s V_7 ldstr resources/9875193 call System.Byte[] 6yeDM3jb9zHe.1mcLK7dmzgJ2W::Jb0j9wmH(System.String) stloc.s V_8 br.s IL_00BF: ldloc.s V_8 nop <null> nop <null> ldloc.s V_7 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_10 ldloc.s V_10 brtrue.s IL_008B: ldloc.s V_7 ldloc.s V_8 castclass System.Byte[] call System.Void 6yeDM3jb9zHe.pn8F5Bwr_0yDS/yq3BF9ir6xdXAz.qQc2i7Za3Yo::Gw8yc(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_11 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00ED: nop nop <null> ret <null>

3fbce05e044eba074b638e4731ff1c3e (1.23 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
6yeDM3jb9zHe.g.resources
6yeDM3jb9zHe.Resources.resources
67a9ac7b3d0f29.Resources.resources
e4fed31d0
[NBF]root.Data
e4fed31d1
[NBF]root.Data
e4fed31d10
[NBF]root.Data
e4fed31d11
[NBF]root.Data
e4fed31d12
[NBF]root.Data
e4fed31d13
[NBF]root.Data
e4fed31d14
[NBF]root.Data
e4fed31d15
[NBF]root.Data
e4fed31d16
[NBF]root.Data
e4fed31d17
[NBF]root.Data
e4fed31d18
[NBF]root.Data
e4fed31d19
[NBF]root.Data
e4fed31d2
[NBF]root.Data
e4fed31d20
[NBF]root.Data
e4fed31d21
[NBF]root.Data
e4fed31d22
[NBF]root.Data
e4fed31d23
[NBF]root.Data
e4fed31d24
[NBF]root.Data
e4fed31d25
[NBF]root.Data
e4fed31d26
[NBF]root.Data
e4fed31d27
[NBF]root.Data
e4fed31d28
[NBF]root.Data
e4fed31d29
[NBF]root.Data
e4fed31d3
[NBF]root.Data
e4fed31d30
[NBF]root.Data
e4fed31d31
[NBF]root.Data
e4fed31d32
[NBF]root.Data
e4fed31d33
[NBF]root.Data
e4fed31d34
[NBF]root.Data
e4fed31d35
[NBF]root.Data
e4fed31d36
[NBF]root.Data
e4fed31d37
[NBF]root.Data
e4fed31d38
[NBF]root.Data
e4fed31d39
[NBF]root.Data
e4fed31d4
[NBF]root.Data
e4fed31d40
[NBF]root.Data
e4fed31d41
[NBF]root.Data
e4fed31d5
[NBF]root.Data
e4fed31d6
[NBF]root.Data
e4fed31d7
[NBF]root.Data
e4fed31d8
[NBF]root.Data
e4fed31d9
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙