Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 5d14a18e3866d2473923562c7d54627a
Size: 1.44 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 5d14a18e3866d2473923562c7d54627a
Sha1 3bd9fcf6231a5d2f66a57454785c7e05b3bc4138
Sha256 528d68f078493c4e45e52387fcf4e69830d0ef9052e7c2ba14a4437b08c594e3
Sha384 23c4522342f2a6b7f9f1c5bec80bf0e411e8e12c740ec017d445e4f5d1e1fccf49e3e59cf545f5a72dcd5e177feec2ee
Sha512 4dc6691a893181d603013c3d5c841233921447c462b8d97139c11ab4d2f8c69fc9ec421c3debdf4f08f9a7e8d94cfde907a3cdfdeab6a17e73e357d141294324
SSDeep 24576:h/Vx8nAd+KSVAMtozRPqeCKLEI607cVI1rdQBnrTe7canR//ycRhf80tl/:h/Vx8yqszYI6AcVGBmryzByGEaZ
TLSH C36533518060A7AEC7CB25B04E3FD9C750A59B60B57976061D6B0CC11FE9C8EFA1B372
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Tjvdoagke.Properties.Resources.resources
Rjxhtpn
Name Value
Module Name
Nowe zamówienie.exe
Full Name
Nowe zamówienie.exe
EntryPoint
System.Void Tjvdoagke.Lqxnpsrzft::Main()
Scope Name
Nowe zamówienie.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Nowe zamówienie
Assembly Version
1.0.2125.23747
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
6
Main Method
System.Void Tjvdoagke.Lqxnpsrzft::Main()
Main IL Instruction Count
11
Main IL
ldsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0
dup <null>
brtrue IL_0022: call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>)
pop <null>
ldsfld Tjvdoagke.Lqxnpsrzft/<>c Tjvdoagke.Lqxnpsrzft/<>c::<>9
ldftn System.Void Tjvdoagke.Lqxnpsrzft/<>c::<Main>b__0_0(System.IO.MemoryStream)
newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0
call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>)
ret <null>
Module Name
Nowe zamówienie.exe
Full Name
Nowe zamówienie.exe
EntryPoint
System.Void Tjvdoagke.Lqxnpsrzft::Main()
Scope Name
Nowe zamówienie.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Nowe zamówienie
Assembly Version
1.0.2125.23747
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
6
Main Method
System.Void Tjvdoagke.Lqxnpsrzft::Main()
Main IL Instruction Count
11
Main IL
ldsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0
dup <null>
brtrue IL_0022: call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>)
pop <null>
ldsfld Tjvdoagke.Lqxnpsrzft/<>c Tjvdoagke.Lqxnpsrzft/<>c::<>9
ldftn System.Void Tjvdoagke.Lqxnpsrzft/<>c::<Main>b__0_0(System.IO.MemoryStream)
newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.Action`1<System.IO.MemoryStream> Tjvdoagke.Lqxnpsrzft/<>c::<>9__0_0
call System.Void Tjvdoagke.Lqxnpsrzft::Spnmvo(System.Action`1<System.IO.MemoryStream>)
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙