Suspicious
Suspect

44ae176d840658f396b4b5c32bdef1e4

Share on LinkedIn
Print
PE Executable
MD5: 44ae176d840658f396b4b5c32bdef1e4
Size: 591.36 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 44ae176d840658f396b4b5c32bdef1e4
Sha1 1ccb73689b7c341c36de790ed21b3f6e71d5d741
Sha256 f2798987ff79bfd4a9cf2b5877ae520d4ed823912f5338e9bf3c4735c70859e2
Sha384 91fcc7b4da9d9cbd326b4e744f4266f4e111975f36556f6138551f090c54dd647fa27cf16afa1326d9ff6d282a4637e7
Sha512 e0e33aba6ed97a67270349e41d8956c343c43e59b1b59c97c03b6ea637117081cdb452629fac3a38250815519464bc11d2ec4a9e451cbf86536b941248258e5a
SSDeep 12288:q9EDTUrDrnSyb6fZFnkOCcuIMGFXeAGRbeXu/t1vsafGuOwUScOr0c+hgWZ:q9E/6QRFFurSXe7RbL/tejuySvY3gWZ
TLSH 7CC42309D399F43AC7A08F76B4FB0E400FF5A9619193E22E16EC5B192A97363CF57016
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Zuddowwluqb.Properties.Resources.resources
Yzecw
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Zuddowwluqb.exe
Full Name
Zuddowwluqb.exe
EntryPoint
System.Void Zuddowwluqb.Qjgjzhj::Main()
Scope Name
Zuddowwluqb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Zuddowwluqb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
36
Main Method
System.Void Zuddowwluqb.Qjgjzhj::Main()
Main IL Instruction Count
20
Main IL
br IL_0006: newobj System.Void Zuddowwluqb.Mqqsbpjzk::.ctor()
ret <null>
newobj System.Void Zuddowwluqb.Mqqsbpjzk::.ctor()
stloc.s V_0
br IL_0012: nop
nop <null>
ldloc.s V_0
call System.Byte[] Zuddowwluqb.Properties.Beettf::get_Yzecw()
ldsfld System.Byte[] Zuddowwluqb.Sorting.TransactionSorter::editorAuthenticators
ldsfld System.Byte[] Zuddowwluqb.Sorting.TransactionSorter::dividedSorterItems
ldstr s5tZ7NVcv1nXcglqpMs.G4QI74Vm3J1oShdqHeq
ldstr cYsVAVajZg
ldnull <null>
callvirt System.Void Zuddowwluqb.Mqqsbpjzk::Ysujfkdf(System.Byte[],System.Byte[],System.Byte[],System.String,System.String,System.Object[])
br IL_0039: leave IL_0005
leave IL_0005: ret
pop <null>
br IL_0044: leave IL_0005
leave IL_0005: ret
br IL_0005: ret
Module Name
Zuddowwluqb.exe
Full Name
Zuddowwluqb.exe
EntryPoint
System.Void Zuddowwluqb.Qjgjzhj::Main()
Scope Name
Zuddowwluqb.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Zuddowwluqb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
36
Main Method
System.Void Zuddowwluqb.Qjgjzhj::Main()
Main IL Instruction Count
20
Main IL
br IL_0006: newobj System.Void Zuddowwluqb.Mqqsbpjzk::.ctor()
ret <null>
newobj System.Void Zuddowwluqb.Mqqsbpjzk::.ctor()
stloc.s V_0
br IL_0012: nop
nop <null>
ldloc.s V_0
call System.Byte[] Zuddowwluqb.Properties.Beettf::get_Yzecw()
ldsfld System.Byte[] Zuddowwluqb.Sorting.TransactionSorter::editorAuthenticators
ldsfld System.Byte[] Zuddowwluqb.Sorting.TransactionSorter::dividedSorterItems
ldstr s5tZ7NVcv1nXcglqpMs.G4QI74Vm3J1oShdqHeq
ldstr cYsVAVajZg
ldnull <null>
callvirt System.Void Zuddowwluqb.Mqqsbpjzk::Ysujfkdf(System.Byte[],System.Byte[],System.Byte[],System.String,System.String,System.Object[])
br IL_0039: leave IL_0005
leave IL_0005: ret
pop <null>
br IL_0044: leave IL_0005
leave IL_0005: ret
br IL_0005: ret
An error has occurred. This application may no longer respond until reloaded. Reload 🗙