Suspicious
Suspect

59bfa642070f371823d05e57297aeee4

PE Executable
|
MD5: 59bfa642070f371823d05e57297aeee4
|
Size: 546.3 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
59bfa642070f371823d05e57297aeee4
Sha1
ac1cc3d181945b5afe7c944683ff17789c1bbf0c
Sha256
b143875445a54cff11ea6ceba531b098ca591818679be82d5a4070d0b1a69170
Sha384
a3dca3d887d93fbcbebe802886e0311e21e5c4d6b011b2cec3dd846ea9d6a6e60a9b78946da401a4074f61eb1c85a6a9
Sha512
19cb014d4f7a26cc7214fc4a300e0d4467993f9d8b72f00aeeb0ed62b39094ce9d85721fe5aebffc7d4bd2b38be1fa145fd9928115f8d6a1ea085f0264c2b7da
SSDeep
6144:LwGRX6MkVPm7+dvXNP4PnSae1S3mve6VlWT8b921gTWx3FFK8+8CMb9522bPp1x:LBBYdfR4t3mvPVle8IOed+Z
TLSH
16C4C20CFE91E805DE1E3DB7CFEA15004B7161C1AE2196462109AFFE8B653B359E267C

PeID

.NET executable
HQR data file
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
owlaogoldtpm
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Client.exe

Full Name

Client.exe

EntryPoint

System.Void ysCMAFqf.avXGOyeOGK::tUbxuzyMGymL(System.String[])

Scope Name

Client.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Client

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

1456

Main Method

System.Void ysCMAFqf.avXGOyeOGK::tUbxuzyMGymL(System.String[])

Main IL Instruction Count

56

Main IL

ldc.r8 2252 stloc.0 <null> br IL_00E7: br IL_000F nop <null> ldloc.0 <null> ldc.r8 2261 ceq <null> brfalse IL_0030: nop call System.Void ysCMAFqf.avXGOyeOGK::SmXQseEIHFz() ldc.r8 2268 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 2268 ceq <null> brfalse IL_0092: nop newobj System.Void System.Random::.ctor() nop <null> ldc.r8 4002.530998328093 ldc.r8 2000 call System.Double System.Math::Tan(System.Double) add <null> call System.Int32 System.Convert::ToInt32(System.Double) nop <null> ldc.r8 18000000 ldc.r8 3000 div <null> call System.Int32 System.Convert::ToInt32(System.Double) callvirt System.Int32 System.Random::Next(System.Int32,System.Int32) call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.r8 2270 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 2270 ceq <null> brfalse IL_00B3: nop call System.Void ysCMAFqf.WVakqMUkwpLcuq::ZjVAhWiNe() ldc.r8 2276 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 2252 ceq <null> brfalse IL_00D0: nop nop <null> ldc.r8 2261 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 2276 ceq <null> brfalse IL_00E7: br IL_000F br IL_00EC: ret br IL_000F: nop ret <null>

Module Name

Client.exe

Full Name

Client.exe

EntryPoint

System.Void ysCMAFqf.avXGOyeOGK::tUbxuzyMGymL(System.String[])

Scope Name

Client.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Client

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

1456

Main Method

System.Void ysCMAFqf.avXGOyeOGK::tUbxuzyMGymL(System.String[])

Main IL Instruction Count

56

Main IL

ldc.r8 2252 stloc.0 <null> br IL_00E7: br IL_000F nop <null> ldloc.0 <null> ldc.r8 2261 ceq <null> brfalse IL_0030: nop call System.Void ysCMAFqf.avXGOyeOGK::SmXQseEIHFz() ldc.r8 2268 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 2268 ceq <null> brfalse IL_0092: nop newobj System.Void System.Random::.ctor() nop <null> ldc.r8 4002.530998328093 ldc.r8 2000 call System.Double System.Math::Tan(System.Double) add <null> call System.Int32 System.Convert::ToInt32(System.Double) nop <null> ldc.r8 18000000 ldc.r8 3000 div <null> call System.Int32 System.Convert::ToInt32(System.Double) callvirt System.Int32 System.Random::Next(System.Int32,System.Int32) call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.r8 2270 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 2270 ceq <null> brfalse IL_00B3: nop call System.Void ysCMAFqf.WVakqMUkwpLcuq::ZjVAhWiNe() ldc.r8 2276 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 2252 ceq <null> brfalse IL_00D0: nop nop <null> ldc.r8 2261 stloc.0 <null> nop <null> ldloc.0 <null> ldc.r8 2276 ceq <null> brfalse IL_00E7: br IL_000F br IL_00EC: ret br IL_000F: nop ret <null>

59bfa642070f371823d05e57297aeee4 (546.3 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙