Suspicious
Suspect

4fc2d490abed527182840de772d5a66b

PE Executable
|
MD5: 4fc2d490abed527182840de772d5a66b
|
Size: 1.13 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
4fc2d490abed527182840de772d5a66b
Sha1
8e6c4228414804093f87d5630833c41f7618d90e
Sha256
8dbda1e5f543feb8eb36c4a15d3bde7bcb18524713fd21d5560a23f5965dbaee
Sha384
807c2e0d6b5bc572c522ee6cd056624066657c20e942a5fbc14a71df8c666710c5644043f2a1a7ae40475f303e73e861
Sha512
2482561d0a96ee3c8e306596722fdb00b7c77005dafb19c912542aa3a6c5228b30b2d7c69029a16ad827c027e37ac2c8f94013e5c7b4918df68cd6717340dc3a
SSDeep
12288:0va7Tr5JthWh2FKioSNiVeGkkT7XnTdnyXMBkkGYSDcbluzdJPb4SqRgkAjZG2U0:ht0hzioSNaeGkOjdYHDAizPnqRgj13n
TLSH
F135D0D617E42D90E07E67B45A67A12443F2B0C7DC33C36C0A88E2DA1B737556EC53AA

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
euromade.g.resources
euromade.euromade.resources
f8faa5f8ae8701.Resources.resources
485311bc0
[NBF]root.Data
485311bc1
[NBF]root.Data
485311bc10
[NBF]root.Data
485311bc11
[NBF]root.Data
485311bc12
[NBF]root.Data
485311bc13
[NBF]root.Data
485311bc14
[NBF]root.Data
485311bc15
[NBF]root.Data
485311bc16
[NBF]root.Data
485311bc17
[NBF]root.Data
485311bc18
[NBF]root.Data
485311bc19
[NBF]root.Data
485311bc2
[NBF]root.Data
485311bc20
[NBF]root.Data
485311bc21
[NBF]root.Data
485311bc22
[NBF]root.Data
485311bc23
[NBF]root.Data
485311bc3
[NBF]root.Data
485311bc4
[NBF]root.Data
485311bc5
[NBF]root.Data
485311bc6
[NBF]root.Data
485311bc7
[NBF]root.Data
485311bc8
[NBF]root.Data
485311bc9
[NBF]root.Data
Informations
Name
Value
Module Name

euromade

Full Name

euromade

EntryPoint

System.Void Xq8m6R.Yz15Wd::x9ZGp1()

Scope Name

euromade

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

euromade

Assembly Version

2.3.8.1

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

2618

Main Method

System.Void Xq8m6R.Yz15Wd::x9ZGp1()

Main IL Instruction Count

86

Main IL

nop <null> nop <null> ldc.i4.1 <null> stloc.0 <null> nop <null> ldloc.0 <null> ldc.i4.s 24 cgt <null> ldc.i4.0 <null> ceq <null> stloc.s V_5 ldloc.s V_5 brfalse.s IL_0019: nop ldc.i4.s 24 stloc.0 <null> nop <null> br.s IL_002B: nop nop <null> ldloc.0 <null> ldc.i4.s 24 clt <null> stloc.s V_6 ldloc.s V_6 brfalse.s IL_0029: nop ldc.i4.s 24 stloc.0 <null> nop <null> nop <null> nop <null> nop <null> ldloc.0 <null> ldc.i4.s 24 rem <null> ldc.i4.0 <null> ceq <null> stloc.s V_7 ldloc.s V_7 brfalse.s IL_0004: nop newobj System.Void System.Collections.Generic.List`1<System.Object>::.ctor() stloc.1 <null> ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> stloc.s V_8 ldc.i4.0 <null> stloc.s V_9 br.s IL_0057: ldloc.s V_9 ldloc.1 <null> ldnull <null> callvirt System.Void System.Collections.Generic.List`1<System.Object>::Add(System.Object) nop <null> ldloc.s V_9 ldc.i4.1 <null> add.ovf <null> stloc.s V_9 ldloc.s V_9 ldloc.s V_8 ble.s IL_0049: ldloc.1 ldloc.1 <null> callvirt System.Object[] System.Collections.Generic.List`1<System.Object>::ToArray() stloc.2 <null> ldstr resources/88721.png call System.Byte[] Xq8m6R.r5KEi4::x0SRy6(System.String) stloc.3 <null> ldloc.3 <null> call System.Byte[] Xq8m6R.Nd79Pw::Pc7z8N(System.Byte[]) stloc.s V_4 ldloc.2 <null> ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldloc.s V_4 stelem.ref <null> ldloc.2 <null> ldloc.0 <null> call System.Void Xq8m6R.w0AHx::b6Q0Ax(System.Object[],System.Int32) nop <null> leave.s IL_0098: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_10 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0098: nop nop <null> ret <null>

Module Name

euromade

Full Name

euromade

EntryPoint

System.Void Xq8m6R.Yz15Wd::x9ZGp1()

Scope Name

euromade

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

euromade

Assembly Version

2.3.8.1

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

2618

Main Method

System.Void Xq8m6R.Yz15Wd::x9ZGp1()

Main IL Instruction Count

86

Main IL

nop <null> nop <null> ldc.i4.1 <null> stloc.0 <null> nop <null> ldloc.0 <null> ldc.i4.s 24 cgt <null> ldc.i4.0 <null> ceq <null> stloc.s V_5 ldloc.s V_5 brfalse.s IL_0019: nop ldc.i4.s 24 stloc.0 <null> nop <null> br.s IL_002B: nop nop <null> ldloc.0 <null> ldc.i4.s 24 clt <null> stloc.s V_6 ldloc.s V_6 brfalse.s IL_0029: nop ldc.i4.s 24 stloc.0 <null> nop <null> nop <null> nop <null> nop <null> ldloc.0 <null> ldc.i4.s 24 rem <null> ldc.i4.0 <null> ceq <null> stloc.s V_7 ldloc.s V_7 brfalse.s IL_0004: nop newobj System.Void System.Collections.Generic.List`1<System.Object>::.ctor() stloc.1 <null> ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> stloc.s V_8 ldc.i4.0 <null> stloc.s V_9 br.s IL_0057: ldloc.s V_9 ldloc.1 <null> ldnull <null> callvirt System.Void System.Collections.Generic.List`1<System.Object>::Add(System.Object) nop <null> ldloc.s V_9 ldc.i4.1 <null> add.ovf <null> stloc.s V_9 ldloc.s V_9 ldloc.s V_8 ble.s IL_0049: ldloc.1 ldloc.1 <null> callvirt System.Object[] System.Collections.Generic.List`1<System.Object>::ToArray() stloc.2 <null> ldstr resources/88721.png call System.Byte[] Xq8m6R.r5KEi4::x0SRy6(System.String) stloc.3 <null> ldloc.3 <null> call System.Byte[] Xq8m6R.Nd79Pw::Pc7z8N(System.Byte[]) stloc.s V_4 ldloc.2 <null> ldloc.0 <null> ldc.i4.1 <null> sub.ovf <null> ldloc.s V_4 stelem.ref <null> ldloc.2 <null> ldloc.0 <null> call System.Void Xq8m6R.w0AHx::b6Q0Ax(System.Object[],System.Int32) nop <null> leave.s IL_0098: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_10 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0098: nop nop <null> ret <null>

Artefacts
Name
Value
Embedded Resources

4

Suspicious Type Names (1-2 chars)

0

4fc2d490abed527182840de772d5a66b (1.13 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
euromade.g.resources
euromade.euromade.resources
f8faa5f8ae8701.Resources.resources
485311bc0
[NBF]root.Data
485311bc1
[NBF]root.Data
485311bc10
[NBF]root.Data
485311bc11
[NBF]root.Data
485311bc12
[NBF]root.Data
485311bc13
[NBF]root.Data
485311bc14
[NBF]root.Data
485311bc15
[NBF]root.Data
485311bc16
[NBF]root.Data
485311bc17
[NBF]root.Data
485311bc18
[NBF]root.Data
485311bc19
[NBF]root.Data
485311bc2
[NBF]root.Data
485311bc20
[NBF]root.Data
485311bc21
[NBF]root.Data
485311bc22
[NBF]root.Data
485311bc23
[NBF]root.Data
485311bc3
[NBF]root.Data
485311bc4
[NBF]root.Data
485311bc5
[NBF]root.Data
485311bc6
[NBF]root.Data
485311bc7
[NBF]root.Data
485311bc8
[NBF]root.Data
485311bc9
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
Embedded Resources

4

4fc2d490abed527182840de772d5a66b

Suspicious Type Names (1-2 chars)

0

4fc2d490abed527182840de772d5a66b

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙