Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
Name Value
Module Name
DJoc.exe
Full Name
DJoc.exe
EntryPoint
System.Void BLPuxFYiiejR3JaYmpF.VVogfTYKbTq3Etn7gbG::R9DYtT0hLt()
Scope Name
DJoc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DJoc
Assembly Version
3.2.1.3
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
46
Main Method
System.Void BLPuxFYiiejR3JaYmpF.VVogfTYKbTq3Etn7gbG::R9DYtT0hLt()
Main IL Instruction Count
29
Main IL
br.s IL_0007: call System.Void a3yQwEe7L8VcXtWGdmH.JcaqmmedPE46ZOdVw6e::Y51Zs4pXxS()
call <null>
call System.Void a3yQwEe7L8VcXtWGdmH.JcaqmmedPE46ZOdVw6e::Y51Zs4pXxS()
ldsfld JdvXYgLXlHOcw3dulCJ JdvXYgLXlHOcw3dulCJ::F66LpbRfh7
call System.Void JdvXYgLXlHOcw3dulCJ::x9SfsFQQmK(JdvXYgLXlHOcw3dulCJ)
ldc.i4.0 <null>
ldsfld dg42VVLncNul3RFYqIG dg42VVLncNul3RFYqIG::a0LLOpa0GO
call System.Void dg42VVLncNul3RFYqIG::x9SfsFQQmK(System.Boolean,dg42VVLncNul3RFYqIG)
call System.Void uxyYfrey7MS0kNX9mlx.TyDquHeDn9HOHSlNwKB::IqOxKxhCSV()
ldc.i4 690195659
ldc.i4 4
shr <null>
ldc.i4 1229483333
xor <null>
ldsfld <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee} <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee}::m_b26b9211ec1f412fa298148eb6e930a1
ldfld System.Int32 <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee}::m_4836750f159e4750846e9daf6dab5226
xor <null>
call System.String y4fxLKYjtsarYTjoygQ.VbMqu5YVIG4EhcVZrDu::i86JfmHlec(System.Int32)
ldc.i4 -443191877
ldc.i4 -932639772
xor <null>
ldsfld <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee} <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee}::m_b26b9211ec1f412fa298148eb6e930a1
ldfld System.Int32 <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee}::m_9282751216c74fa9a50dbbaf5eb46e50
xor <null>
call System.String y4fxLKYjtsarYTjoygQ.VbMqu5YVIG4EhcVZrDu::i86JfmHlec(System.Int32)
newobj System.Void Rental.MainForm::.ctor(System.String,System.String)
ldsfld ukJUNiLvR31qHt2cR8B ukJUNiLvR31qHt2cR8B::C0gLFdYrL1
call System.Void ukJUNiLvR31qHt2cR8B::x9SfsFQQmK(System.Windows.Forms.Form,ukJUNiLvR31qHt2cR8B)
ret <null>
Module Name
DJoc.exe
Full Name
DJoc.exe
EntryPoint
System.Void BLPuxFYiiejR3JaYmpF.VVogfTYKbTq3Etn7gbG::R9DYtT0hLt()
Scope Name
DJoc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DJoc
Assembly Version
3.2.1.3
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
46
Main Method
System.Void BLPuxFYiiejR3JaYmpF.VVogfTYKbTq3Etn7gbG::R9DYtT0hLt()
Main IL Instruction Count
29
Main IL
br.s IL_0007: call System.Void a3yQwEe7L8VcXtWGdmH.JcaqmmedPE46ZOdVw6e::Y51Zs4pXxS()
call <null>
call System.Void a3yQwEe7L8VcXtWGdmH.JcaqmmedPE46ZOdVw6e::Y51Zs4pXxS()
ldsfld JdvXYgLXlHOcw3dulCJ JdvXYgLXlHOcw3dulCJ::F66LpbRfh7
call System.Void JdvXYgLXlHOcw3dulCJ::x9SfsFQQmK(JdvXYgLXlHOcw3dulCJ)
ldc.i4.0 <null>
ldsfld dg42VVLncNul3RFYqIG dg42VVLncNul3RFYqIG::a0LLOpa0GO
call System.Void dg42VVLncNul3RFYqIG::x9SfsFQQmK(System.Boolean,dg42VVLncNul3RFYqIG)
call System.Void uxyYfrey7MS0kNX9mlx.TyDquHeDn9HOHSlNwKB::IqOxKxhCSV()
ldc.i4 690195659
ldc.i4 4
shr <null>
ldc.i4 1229483333
xor <null>
ldsfld <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee} <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee}::m_b26b9211ec1f412fa298148eb6e930a1
ldfld System.Int32 <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee}::m_4836750f159e4750846e9daf6dab5226
xor <null>
call System.String y4fxLKYjtsarYTjoygQ.VbMqu5YVIG4EhcVZrDu::i86JfmHlec(System.Int32)
ldc.i4 -443191877
ldc.i4 -932639772
xor <null>
ldsfld <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee} <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee}::m_b26b9211ec1f412fa298148eb6e930a1
ldfld System.Int32 <Module>{279908d9-73a0-4b1e-bd8d-67fedcf72cee}::m_9282751216c74fa9a50dbbaf5eb46e50
xor <null>
call System.String y4fxLKYjtsarYTjoygQ.VbMqu5YVIG4EhcVZrDu::i86JfmHlec(System.Int32)
newobj System.Void Rental.MainForm::.ctor(System.String,System.String)
ldsfld ukJUNiLvR31qHt2cR8B ukJUNiLvR31qHt2cR8B::C0gLFdYrL1
call System.Void ukJUNiLvR31qHt2cR8B::x9SfsFQQmK(System.Windows.Forms.Form,ukJUNiLvR31qHt2cR8B)
ret <null>
Embedded Resources UNKNWOWNsuspect
5huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙