Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
9Tz_s5LqPw4.Xk4oy.resources
7571fbae97f8f6.Resources.resources
3561b94a0
[NBF]root.Data
3561b94a1
[NBF]root.Data
3561b94a10
[NBF]root.Data
3561b94a11
[NBF]root.Data
3561b94a12
[NBF]root.Data
3561b94a13
[NBF]root.Data
3561b94a14
[NBF]root.Data
3561b94a15
[NBF]root.Data
3561b94a16
[NBF]root.Data
3561b94a17
[NBF]root.Data
3561b94a18
[NBF]root.Data
3561b94a19
[NBF]root.Data
3561b94a2
[NBF]root.Data
3561b94a20
[NBF]root.Data
3561b94a21
[NBF]root.Data
3561b94a22
[NBF]root.Data
3561b94a23
[NBF]root.Data
3561b94a24
[NBF]root.Data
3561b94a25
[NBF]root.Data
3561b94a26
[NBF]root.Data
3561b94a27
[NBF]root.Data
3561b94a28
[NBF]root.Data
3561b94a29
[NBF]root.Data
3561b94a3
[NBF]root.Data
3561b94a30
[NBF]root.Data
3561b94a31
[NBF]root.Data
3561b94a32
[NBF]root.Data
3561b94a33
[NBF]root.Data
3561b94a34
[NBF]root.Data
3561b94a35
[NBF]root.Data
3561b94a36
[NBF]root.Data
3561b94a37
[NBF]root.Data
3561b94a38
[NBF]root.Data
3561b94a39
[NBF]root.Data
3561b94a4
[NBF]root.Data
3561b94a40
[NBF]root.Data
3561b94a41
[NBF]root.Data
3561b94a42
[NBF]root.Data
3561b94a5
[NBF]root.Data
3561b94a6
[NBF]root.Data
3561b94a7
[NBF]root.Data
3561b94a8
[NBF]root.Data
3561b94a9
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
9Tz_s5LqPw4
Full Name
9Tz_s5LqPw4
EntryPoint
System.Void 9Tz_s5LqPw4.qm4Hn6AzRd::Gm7k2()
Scope Name
9Tz_s5LqPw4
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
9Tz_s5LqPw4
Assembly Version
4.15.21.244
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
548
Main Method
System.Void 9Tz_s5LqPw4.qm4Hn6AzRd::Gm7k2()
Main IL Instruction Count
7
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
newobj System.Void 9Tz_s5LqPw4.Xk4oy::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
9Tz_s5LqPw4
Full Name
9Tz_s5LqPw4
EntryPoint
System.Void 9Tz_s5LqPw4.qm4Hn6AzRd::Gm7k2()
Scope Name
9Tz_s5LqPw4
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
9Tz_s5LqPw4
Assembly Version
4.15.21.244
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
548
Main Method
System.Void 9Tz_s5LqPw4.qm4Hn6AzRd::Gm7k2()
Main IL Instruction Count
7
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
newobj System.Void 9Tz_s5LqPw4.Xk4oy::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙