Suspicious
Suspect

44ae176d840658f396b4b5c32bdef1e4

PE Executable
MD5: 44ae176d840658f396b4b5c32bdef1e4
Size: 591.36 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 44ae176d840658f396b4b5c32bdef1e4
Sha1 1ccb73689b7c341c36de790ed21b3f6e71d5d741
Sha256 f2798987ff79bfd4a9cf2b5877ae520d4ed823912f5338e9bf3c4735c70859e2
Sha384 91fcc7b4da9d9cbd326b4e744f4266f4e111975f36556f6138551f090c54dd647fa27cf16afa1326d9ff6d282a4637e7
Sha512 e0e33aba6ed97a67270349e41d8956c343c43e59b1b59c97c03b6ea637117081cdb452629fac3a38250815519464bc11d2ec4a9e451cbf86536b941248258e5a
SSDeep 12288:q9EDTUrDrnSyb6fZFnkOCcuIMGFXeAGRbeXu/t1vsafGuOwUScOr0c+hgWZ:q9E/6QRFFurSXe7RbL/tejuySvY3gWZ
TLSH 7CC42309D399F43AC7A08F76B4FB0E400FF5A9619193E22E16EC5B192A97363CF57016
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Zuddowwluqb.Properties.Resources.resources
Yzecw
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Zuddowwluqb.exe
Full Name
Zuddowwluqb.exe
EntryPoint
System.Void Zuddowwluqb.Qjgjzhj::Main()
Scope Name
Zuddowwluqb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Zuddowwluqb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
36
Main Method
System.Void Zuddowwluqb.Qjgjzhj::Main()
Main IL Instruction Count
20
Main IL
br IL_0006: newobj System.Void Zuddowwluqb.Mqqsbpjzk::.ctor()
ret <null>
newobj System.Void Zuddowwluqb.Mqqsbpjzk::.ctor()
stloc.s V_0
br IL_0012: nop
nop <null>
ldloc.s V_0
call System.Byte[] Zuddowwluqb.Properties.Beettf::get_Yzecw()
ldsfld System.Byte[] Zuddowwluqb.Sorting.TransactionSorter::editorAuthenticators
ldsfld System.Byte[] Zuddowwluqb.Sorting.TransactionSorter::dividedSorterItems
ldstr s5tZ7NVcv1nXcglqpMs.G4QI74Vm3J1oShdqHeq
ldstr cYsVAVajZg
ldnull <null>
callvirt System.Void Zuddowwluqb.Mqqsbpjzk::Ysujfkdf(System.Byte[],System.Byte[],System.Byte[],System.String,System.String,System.Object[])
br IL_0039: leave IL_0005
leave IL_0005: ret
pop <null>
br IL_0044: leave IL_0005
leave IL_0005: ret
br IL_0005: ret
Module Name
Zuddowwluqb.exe
Full Name
Zuddowwluqb.exe
EntryPoint
System.Void Zuddowwluqb.Qjgjzhj::Main()
Scope Name
Zuddowwluqb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Zuddowwluqb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
36
Main Method
System.Void Zuddowwluqb.Qjgjzhj::Main()
Main IL Instruction Count
20
Main IL
br IL_0006: newobj System.Void Zuddowwluqb.Mqqsbpjzk::.ctor()
ret <null>
newobj System.Void Zuddowwluqb.Mqqsbpjzk::.ctor()
stloc.s V_0
br IL_0012: nop
nop <null>
ldloc.s V_0
call System.Byte[] Zuddowwluqb.Properties.Beettf::get_Yzecw()
ldsfld System.Byte[] Zuddowwluqb.Sorting.TransactionSorter::editorAuthenticators
ldsfld System.Byte[] Zuddowwluqb.Sorting.TransactionSorter::dividedSorterItems
ldstr s5tZ7NVcv1nXcglqpMs.G4QI74Vm3J1oShdqHeq
ldstr cYsVAVajZg
ldnull <null>
callvirt System.Void Zuddowwluqb.Mqqsbpjzk::Ysujfkdf(System.Byte[],System.Byte[],System.Byte[],System.String,System.String,System.Object[])
br IL_0039: leave IL_0005
leave IL_0005: ret
pop <null>
br IL_0044: leave IL_0005
leave IL_0005: ret
br IL_0005: ret
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Zuddowwluqb.Properties.Resources.resources
Yzecw
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙