Malicious
Malicious

48e1fdaf7662517c4e0f968966d4d7b0

PE Executable
|
MD5: 48e1fdaf7662517c4e0f968966d4d7b0
|
Size: 133.63 KB
|
application/x-dosexec

Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
48e1fdaf7662517c4e0f968966d4d7b0
Sha1
6320e1973e714027f3d4280c125ff36f51848f81
Sha256
f9eda741e36de984f5764c76429ada284101b74abba47b708ac175c49f8227fe
Sha384
70908f7bcb6790a06b3be005cc8f359418a37c5f3908fbdf54793411fb5c7350c8f077e39051aa582ac92399eb9a4821
Sha512
19a554d79f028a0d86e584b62e997fcf8111f57aa47557dbe6a0dd2d0b96bc4687e9dbc4f27cb63812c22db070e7fea63d5c03fcc1e499c68a9ac9e7abdf7f63
SSDeep
3072:9+XTGb9aByNHS9IvEMb5ssLsL9wvxdKgbY:AG5aaEMbpTTb
TLSH
27D318592BE49814E1FFA97302706115C375F8130A6ACF1D1BC2B86D2A7E6E1CE16F93

PeID

Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
lfwhUWZlmFnGhDYPudAJ.Resources.resources
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

lfwhUWZlmFnGhDYPudAJ.exe

Full Name

lfwhUWZlmFnGhDYPudAJ.exe

EntryPoint

System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Main()

Scope Name

lfwhUWZlmFnGhDYPudAJ.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

lfwhUWZlmFnGhDYPudAJ

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

1479

Main Method

System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Main()

Main IL Instruction Count

160

Main IL

nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::U�߂�Ԝ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::˨-�ë�() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::«ٚیϒA() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::ɮAױƟ뜸() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::뫆䇹޹皍�() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Ωƌջ븤�() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::�鈇-�؜() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Օ븤恁ޤ޻() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::꼺ӥʭݶZ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::콪Ц̧�() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::מc츠᳼�() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::�Rɩôå() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::�ŚΑşջ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::�恁޻뫆c() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::հΠܪ�ׁ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::޸ƌׁ—Օ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::ӛӤֵŎŔ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Ԝᔖל׃œ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Юٗ-B�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ľ�鈇Ɯ�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�şŁɛٷ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�ɛӚŎӓ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Αג‰ִK() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ӚӺ츠^�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ӻ�εҏɇ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ҡľ�ʤ޹() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ЅԌRƟ�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::츠ƌ�ٚ콪() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::B،�Ŵ㹃() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::یג—z«() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::츠לę鈟ٷ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ɛیˤ�j() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ʭג�ɩҢ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::᳼ިܣבܣ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ŏiƌ�ޤ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Uˤۨ�鈇() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ꓞ�΅뜸У() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�ݝ�թל() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::сήʪڿٵ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::tWڿ޸O() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ѕȩ̄ߟŁ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::⥤չ盀꾯ᆳ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::؝Ц׉�ľ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::iųܪׁņ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::̲߻ٚӓų() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�Uթۚک() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�ٕ@鈟�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ī߻Ų㹃恁() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ִņ븤հƚ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ǎŔޗ�䇹() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ɵ븤��Ω() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::«Ī콪åή() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::��ӥ�Ò() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ò�˳�蠺() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::^�şΑ�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ӓױņ�Ɯ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ٵЮ���() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::հ盀ӓ߂B() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�ב�ĂÒ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�m�ɢ�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ôA2䇹̀() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ٕmٕ쐬̆() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::׃ٵŁ퓜ņ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�Ӻٕ֏�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::¾ٚک«Ϙ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�޴嵱ʪ㹃() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Մųzʓٷ() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::&�m΅() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::ҟεZ�ҏ() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::ʪٷǎ콪&() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::�츠Bܣᆳ() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::丐˳Օٗ�() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::ŧִӤʤک() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::��t쐬ܣ() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::Ųɛ޴B泮() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::m�Ӥ،¾() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::iٚٚå—() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Ң똛Թ泮ִ() nop <null> call System.Void System.Windows.Forms.Application::Run() nop <null> ret <null>

Module Name

lfwhUWZlmFnGhDYPudAJ.exe

Full Name

lfwhUWZlmFnGhDYPudAJ.exe

EntryPoint

System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Main()

Scope Name

lfwhUWZlmFnGhDYPudAJ.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

lfwhUWZlmFnGhDYPudAJ

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

1479

Main Method

System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Main()

Main IL Instruction Count

160

Main IL

nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::U�߂�Ԝ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::˨-�ë�() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::«ٚیϒA() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::ɮAױƟ뜸() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::뫆䇹޹皍�() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Ωƌջ븤�() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::�鈇-�؜() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Օ븤恁ޤ޻() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::꼺ӥʭݶZ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::콪Ц̧�() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::מc츠᳼�() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::�Rɩôå() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::�ŚΑşջ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::�恁޻뫆c() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::հΠܪ�ׁ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::޸ƌׁ—Օ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::ӛӤֵŎŔ() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Ԝᔖל׃œ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Юٗ-B�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ľ�鈇Ɯ�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�şŁɛٷ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�ɛӚŎӓ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Αג‰ִK() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ӚӺ츠^�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ӻ�εҏɇ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ҡľ�ʤ޹() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ЅԌRƟ�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::츠ƌ�ٚ콪() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::B،�Ŵ㹃() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::یג—z«() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::츠לę鈟ٷ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ɛیˤ�j() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ʭג�ɩҢ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::᳼ިܣבܣ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ŏiƌ�ޤ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Uˤۨ�鈇() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ꓞ�΅뜸У() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�ݝ�թל() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::сήʪڿٵ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::tWڿ޸O() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ѕȩ̄ߟŁ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::⥤չ盀꾯ᆳ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::؝Ц׉�ľ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::iųܪׁņ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::̲߻ٚӓų() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�Uթۚک() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�ٕ@鈟�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ī߻Ų㹃恁() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ִņ븤հƚ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ǎŔޗ�䇹() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ɵ븤��Ω() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::«Ī콪åή() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::��ӥ�Ò() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Ò�˳�蠺() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::^�şΑ�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ӓױņ�Ɯ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ٵЮ���() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::հ盀ӓ߂B() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�ב�ĂÒ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�m�ɢ�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ôA2䇹̀() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::ٕmٕ쐬̆() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::׃ٵŁ퓜ņ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�Ӻٕ֏�() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::¾ٚک«Ϙ() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::�޴嵱ʪ㹃() nop <null> call System.Void ņᔖUגε.Z¾�Αϫ::Մųzʓٷ() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::&�m΅() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::ҟεZ�ҏ() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::ʪٷǎ콪&() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::�츠Bܣᆳ() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::丐˳Օٗ�() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::ŧִӤʤک() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::��t쐬ܣ() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::Ųɛ޴B泮() nop <null> call System.Void ҟӛс𝄖.�㠰ɛیҢ::m�Ӥ،¾() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::iٚٚå—() nop <null> call System.Void ᔖĪ؉⛊̲.Jٚεٚ�::Ң똛Թ泮ִ() nop <null> call System.Void System.Windows.Forms.Application::Run() nop <null> ret <null>

48e1fdaf7662517c4e0f968966d4d7b0 (133.63 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
lfwhUWZlmFnGhDYPudAJ.Resources.resources
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙