Malicious
Malicious

5f2ff5cfdaa763f0e1b0dbc8f9300f99

PE Executable
|
MD5: 5f2ff5cfdaa763f0e1b0dbc8f9300f99
|
Size: 1.96 MB
|
application/x-dosexec


Print
Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
5f2ff5cfdaa763f0e1b0dbc8f9300f99
Sha1
1b0ffa8e6cb9e27eea2036e1693ff4d7334d53e4
Sha256
8482463c0ecd90421f6c9b4daab13d919d2973f4500a82dfc15b33f013f9aaf2
Sha384
33e6ce9a47403fd9c0f04edcfedf1a394ab93b771475fafc8a752a4932c9dcb624bd9a7486a7209e65a5093ae2926b4e
Sha512
44c8a5feae9191fc252920de9c20cdc9e79295eacb1b41bec85b4476561c3a6534c7680764b84f11c4a80a3e7a61a1476db57dcd7086876cef9aec1fc52ff712
SSDeep
24576:tMa80akIFd84mVx6m2HEZUkEN5FMQNtVQZ3KqF0TyaJBZ3l0XeBjhcbhOtBXg+WB:t4n73/5zQZpGOyBge4hOtRWWDQO9jO
TLSH
C695BF1665A28E77C3646731C1A7013D42E0C7667922EB5F3A1F20D2A917BF18A732F7

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
wDdiYJslG8eJSdKtlK.aKamu3Im44VnSpxXnI
JhbAjBRrchKNddA2Cg.e6oJJAND1WDDulZqnj
ksxyepkmXj9i8OIZPg.0VawoufIZnlgpprU9w
VhP5iTV8q6eGwx4QrG.BMJflfMOv4frhoqlAG
DlLB6967vAwAT72w4p.WR3lAahshgppQVjfXm
O0oBglWDdcw0kOZR46.MOn2LtCZNjtdqux33F
Informations
Name
Value
Module Name

pxqDsBPmp0nY

Full Name

pxqDsBPmp0nY

EntryPoint

System.Void DiOEr1HhNW1Z3SOgJ3s.N6skBlH6CdCSjcAJYgf::rdTHsjN8mH()

Scope Name

pxqDsBPmp0nY

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

SGxDUr5uRrbW2X9YcTIdUkMi5E

Assembly Version

4.1.5.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

47

Main Method

System.Void DiOEr1HhNW1Z3SOgJ3s.N6skBlH6CdCSjcAJYgf::rdTHsjN8mH()

Main IL Instruction Count

43

Main IL

ldc.i4 2 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0054: ldnull call System.Void ba7QaYt3g3bkFydsA16.x04FaytpGuedmp6CWZn::AKJCIuO0VnN() ldc.i4 0 ldsfld <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88} <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_99afd47ba5434dbcaa819731f7243dcb ldfld System.Int32 <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_8fc3ea6f77cd4547bd9960b8ca4c053a brfalse IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) pop <null> ldc.i4 1 br IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) ldnull <null> ldnull <null> newobj System.Void qXtEE3hTNXkuuXT9398.eEduZmhAMBWBn2Vps9q::.ctor(System.String,System.String) call System.Void PBj5mYCdBwhJihn0UMv.UQhNawCHW8cOu8IL32d::msRCxn6cs5(qXtEE3hTNXkuuXT9398.eEduZmhAMBWBn2Vps9q) ldc.i4 3 br IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) newobj System.Void QYkWSgRM6wjVATE2vy2.x7rBqRRV7aj7vbMGhbA::.ctor() pop <null> ldc.i4 0 ldsfld <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88} <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_99afd47ba5434dbcaa819731f7243dcb ldfld System.Int32 <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_4f8e83e3cb2c4b3387ab8253bc91c084 brfalse IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) pop <null> ldc.i4 0 br IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) ldc.i4 289714644 ldc.i4 -1787627977 xor <null> ldc.i4 -1513251673 xor <null> ldsfld <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88} <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_99afd47ba5434dbcaa819731f7243dcb ldfld System.Int32 <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_52adc37ef5d647a492a1f16b07dbdeec xor <null> call System.String jTI5YIupIQQ15I5mxie.BLewDXubd288cO11sF4::rRBu24qpE4(System.Int32) newobj System.Void u0vhXPNksx5808ZL60k.d398R8NMxMwuH5tvJEW::.ctor(System.String) call System.Void u0vhXPNksx5808ZL60k.d398R8NMxMwuH5tvJEW::NKSNfchGc1() ldc.i4 4 br IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) ret <null>

Module Name

pxqDsBPmp0nY

Full Name

pxqDsBPmp0nY

EntryPoint

System.Void DiOEr1HhNW1Z3SOgJ3s.N6skBlH6CdCSjcAJYgf::rdTHsjN8mH()

Scope Name

pxqDsBPmp0nY

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

SGxDUr5uRrbW2X9YcTIdUkMi5E

Assembly Version

4.1.5.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

47

Main Method

System.Void DiOEr1HhNW1Z3SOgJ3s.N6skBlH6CdCSjcAJYgf::rdTHsjN8mH()

Main IL Instruction Count

43

Main IL

ldc.i4 2 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0054: ldnull call System.Void ba7QaYt3g3bkFydsA16.x04FaytpGuedmp6CWZn::AKJCIuO0VnN() ldc.i4 0 ldsfld <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88} <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_99afd47ba5434dbcaa819731f7243dcb ldfld System.Int32 <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_8fc3ea6f77cd4547bd9960b8ca4c053a brfalse IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) pop <null> ldc.i4 1 br IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) ldnull <null> ldnull <null> newobj System.Void qXtEE3hTNXkuuXT9398.eEduZmhAMBWBn2Vps9q::.ctor(System.String,System.String) call System.Void PBj5mYCdBwhJihn0UMv.UQhNawCHW8cOu8IL32d::msRCxn6cs5(qXtEE3hTNXkuuXT9398.eEduZmhAMBWBn2Vps9q) ldc.i4 3 br IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) newobj System.Void QYkWSgRM6wjVATE2vy2.x7rBqRRV7aj7vbMGhbA::.ctor() pop <null> ldc.i4 0 ldsfld <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88} <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_99afd47ba5434dbcaa819731f7243dcb ldfld System.Int32 <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_4f8e83e3cb2c4b3387ab8253bc91c084 brfalse IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) pop <null> ldc.i4 0 br IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) ldc.i4 289714644 ldc.i4 -1787627977 xor <null> ldc.i4 -1513251673 xor <null> ldsfld <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88} <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_99afd47ba5434dbcaa819731f7243dcb ldfld System.Int32 <Module>{1e523589-91ef-49ca-ac66-2ff3e70ede88}::m_52adc37ef5d647a492a1f16b07dbdeec xor <null> call System.String jTI5YIupIQQ15I5mxie.BLewDXubd288cO11sF4::rRBu24qpE4(System.Int32) newobj System.Void u0vhXPNksx5808ZL60k.d398R8NMxMwuH5tvJEW::.ctor(System.String) call System.Void u0vhXPNksx5808ZL60k.d398R8NMxMwuH5tvJEW::NKSNfchGc1() ldc.i4 4 br IL_0012: switch(IL_0054,IL_006A,IL_0030,IL_008F,IL_00C4) ret <null>

5f2ff5cfdaa763f0e1b0dbc8f9300f99 (1.96 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙