Suspicious
Suspect

5d5d3e5f4a60971fa8cf979b1c25cfe9

PE Executable
|
MD5: 5d5d3e5f4a60971fa8cf979b1c25cfe9
|
Size: 125.05 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
5d5d3e5f4a60971fa8cf979b1c25cfe9
Sha1
d7c1df2236695cb1746ed5edbf3fa0a86662250d
Sha256
939a66d4d9702e973dfbcf9144290a7a4f708626fe10f5e004c54974a6774c77
Sha384
c745812d17b40635bc0540b3d7c179eb4cfbac6daf780631a1bc0776ecee0892533a4055799f2723d13ca3ddf1d9d89c
Sha512
989e17fbb9609a62ba0be14761f3e4450db9057e59ca47ecedb9d747bc5879f62bfc967acf64dcaeb9571e25bab59c700856678b7693d684acb230898ddf07bf
SSDeep
384:B0uQypRZmAv2rLrK+Obh3b/cswsLRO8Na8lNhq6ki2lKxiJ4yS+ShjmM6IGBkS9E:Myp39q6rbRO8Na8lDF2zJS+ST6nkh
TLSH
ADC381D9B155C321F925F974F48A9CBD7E1EADC2F45075FD3426B219AA702E0038AE23

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
[Authenticode]_c3e86401.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x1BA00 size 11896 bytes

Module Name

zecue.exe

Full Name

zecue.exe

EntryPoint

System.Void .::()

Scope Name

zecue.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

zecue

Assembly Version

5.5.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

5

Main Method

System.Void .::()

Main IL Instruction Count

48

Main IL

ldc.i4.0 <null> brtrue.s IL_0009: ldstr "s0hAV3IC+OeSyXLah9jCWA==" br.s IL_003D: newobj System.Void .::.ctor() ldc.i4.0 <null> brfalse.s IL_0044: stloc.0 pop <null> ldstr s0hAV3IC+OeSyXLah9jCWA== br.s IL_0047: stloc.1 ldstr W7sBXwcd4uk= ldc.i4.1 <null> brtrue.s IL_004A: stloc.2 pop <null> ldstr AqDBox0RiAcmn8xLt8.xKa0ep6FdsLXZyr4fA br.s IL_004D: stloc.3 ldstr cxXRF0537 br.s IL_0050: stloc.s V_4 ldc.i4.0 <null> brtrue.s IL_0009: ldstr "s0hAV3IC+OeSyXLah9jCWA==" br.s IL_0054: ldloc.2 br.s IL_0057: ldloc.0 br.s IL_005A: ldloc.3 ldloc.1 <null> ldloc.s V_4 call System.Void .::(System.String,.,System.String,System.String,System.String) ldc.i4.0 <null> brtrue.s IL_0009: ldstr "s0hAV3IC+OeSyXLah9jCWA==" leave.s IL_0060: ret newobj System.Void .::.ctor() br.s IL_0005: ldc.i4.0 stloc.0 <null> br.s IL_0009: ldstr "s0hAV3IC+OeSyXLah9jCWA==" stloc.1 <null> br.s IL_0010: ldstr "W7sBXwcd4uk=" stloc.2 <null> br.s IL_0019: ldstr "AqDBox0RiAcmn8xLt8.xKa0ep6FdsLXZyr4fA" stloc.3 <null> br.s IL_0020: ldstr "cxXRF0537" stloc.s V_4 br.s IL_0027: ldc.i4.0 ldloc.2 <null> br.s IL_002C: br.s IL_0057 ldloc.0 <null> br.s IL_002E: br.s IL_005A ldloc.3 <null> br.s IL_0030: ldloc.1 pop <null> leave.s IL_0060: ret ret <null>

Module Name

zecue.exe

Full Name

zecue.exe

EntryPoint

System.Void .::()

Scope Name

zecue.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

zecue

Assembly Version

5.5.3.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

5

Main Method

System.Void .::()

Main IL Instruction Count

48

Main IL

ldc.i4.0 <null> brtrue.s IL_0009: ldstr "s0hAV3IC+OeSyXLah9jCWA==" br.s IL_003D: newobj System.Void .::.ctor() ldc.i4.0 <null> brfalse.s IL_0044: stloc.0 pop <null> ldstr s0hAV3IC+OeSyXLah9jCWA== br.s IL_0047: stloc.1 ldstr W7sBXwcd4uk= ldc.i4.1 <null> brtrue.s IL_004A: stloc.2 pop <null> ldstr AqDBox0RiAcmn8xLt8.xKa0ep6FdsLXZyr4fA br.s IL_004D: stloc.3 ldstr cxXRF0537 br.s IL_0050: stloc.s V_4 ldc.i4.0 <null> brtrue.s IL_0009: ldstr "s0hAV3IC+OeSyXLah9jCWA==" br.s IL_0054: ldloc.2 br.s IL_0057: ldloc.0 br.s IL_005A: ldloc.3 ldloc.1 <null> ldloc.s V_4 call System.Void .::(System.String,.,System.String,System.String,System.String) ldc.i4.0 <null> brtrue.s IL_0009: ldstr "s0hAV3IC+OeSyXLah9jCWA==" leave.s IL_0060: ret newobj System.Void .::.ctor() br.s IL_0005: ldc.i4.0 stloc.0 <null> br.s IL_0009: ldstr "s0hAV3IC+OeSyXLah9jCWA==" stloc.1 <null> br.s IL_0010: ldstr "W7sBXwcd4uk=" stloc.2 <null> br.s IL_0019: ldstr "AqDBox0RiAcmn8xLt8.xKa0ep6FdsLXZyr4fA" stloc.3 <null> br.s IL_0020: ldstr "cxXRF0537" stloc.s V_4 br.s IL_0027: ldc.i4.0 ldloc.2 <null> br.s IL_002C: br.s IL_0057 ldloc.0 <null> br.s IL_002E: br.s IL_005A ldloc.3 <null> br.s IL_0030: ldloc.1 pop <null> leave.s IL_0060: ret ret <null>

5d5d3e5f4a60971fa8cf979b1c25cfe9 (125.05 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙