Suspicious
Suspect

PE Executable
MD5: 5d14a18e3866d2473923562c7d54627a
Size: 1.44 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 5d14a18e3866d2473923562c7d54627a
Sha1 3bd9fcf6231a5d2f66a57454785c7e05b3bc4138
Sha256 528d68f078493c4e45e52387fcf4e69830d0ef9052e7c2ba14a4437b08c594e3
Sha384 23c4522342f2a6b7f9f1c5bec80bf0e411e8e12c740ec017d445e4f5d1e1fccf49e3e59cf545f5a72dcd5e177feec2ee
Sha512 4dc6691a893181d603013c3d5c841233921447c462b8d97139c11ab4d2f8c69fc9ec421c3debdf4f08f9a7e8d94cfde907a3cdfdeab6a17e73e357d141294324
SSDeep 24576:h/Vx8nAd+KSVAMtozRPqeCKLEI607cVI1rdQBnrTe7canR//ycRhf80tl/:h/Vx8yqszYI6AcVGBmryzByGEaZ
TLSH C36533518060A7AEC7CB25B04E3FD9C750A59B60B57976061D6B0CC11FE9C8EFA1B372
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Tjvdoagke.Properties.Resources.resources
Rjxhtpn
Name Value
Module Name
Nowe zamówienie.exe
Full Name
Nowe zamówienie.exe
EntryPoint
System.Void Tjvdoagke.Lqxnpsrzft::Main()
Scope Name
Nowe zamówienie.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Nowe zamówienie
Assembly Version
1.0.2125.23747
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
6
Main Method
System.Void Tjvdoagke.Lqxnpsrzft::Main()
Main IL Instruction Count
11
Main IL
ldsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0
dup <null>
brtrue IL_0022: call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>)
pop <null>
ldsfld Tjvdoagke.Lqxnpsrzft/<>c Tjvdoagke.Lqxnpsrzft/<>c::<>9
ldftn System.Void Tjvdoagke.Lqxnpsrzft/<>c::<Main>b__0_0(System.IO.MemoryStream)
newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0
call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>)
ret <null>
Module Name
Nowe zamówienie.exe
Full Name
Nowe zamówienie.exe
EntryPoint
System.Void Tjvdoagke.Lqxnpsrzft::Main()
Scope Name
Nowe zamówienie.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Nowe zamówienie
Assembly Version
1.0.2125.23747
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
6
Main Method
System.Void Tjvdoagke.Lqxnpsrzft::Main()
Main IL Instruction Count
11
Main IL
ldsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0
dup <null>
brtrue IL_0022: call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>)
pop <null>
ldsfld Tjvdoagke.Lqxnpsrzft/<>c Tjvdoagke.Lqxnpsrzft/<>c::<>9
ldftn System.Void Tjvdoagke.Lqxnpsrzft/<>c::<Main>b__0_0(System.IO.MemoryStream)
newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0
call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Tjvdoagke.Properties.Resources.resources
Rjxhtpn
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙