Suspicious
Suspect

6c203fef991986c1325ba64600c1f47e

PE Executable
|
MD5: 6c203fef991986c1325ba64600c1f47e
|
Size: 136.19 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
6c203fef991986c1325ba64600c1f47e
Sha1
5b90d00387bd66213a3ecadc3015ac7b7ff4740b
Sha256
2ebbc0ecfdc8da987269085bdff3bfef88b555a5557beec2880d81eb58862fd8
Sha384
7985e978aa8a8f8601fd1a5a40615d7dbdf52d769db55ef3736315a1c6220ce2a55fad834c2695d125c883892a9c5326
Sha512
ee022e7acab6ba70aa8c073008fea044b044cb411e0ec08bdba83646a31903f4bbdff9dae35b417b79576b4243329669e2e52240d3f24a3cd4619c341d6251f9
SSDeep
3072:u2vDTuTEp3JyJGjqriMtRXGTi7NVan3yEUClBPN2osNPB:rTAEJtoGTixw3ylOFN
TLSH
10D39BB3FAC7D9E7C544CF3464AB7D25032C82B03D079AE9E9E4213BDD9260589929D3

PeID

Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WindowsFormsApp1.Properties.Resources.resources
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

BhVayAL

Full Name

BhVayAL

EntryPoint

System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::ngTOHfWyBiDRHpgjiKRKUbHzCZoRtkgAUbpTZcRq(System.String[])

Scope Name

BhVayAL

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

WindowsFormsApp1

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

8

Main Method

System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::ngTOHfWyBiDRHpgjiKRKUbHzCZoRtkgAUbpTZcRq(System.String[])

Main IL Instruction Count

50

Main IL

call System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::zSKTbuWpBYWnFGamytmIQeerccWFZmkgTBlcrNyh() call System.String <Module>::LMzmJOoFaa() stloc.0 <null> call System.Byte[] zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::cZpunTVobduFPjAuNsRYxqpoOQteuXUKUeFQOKei() stloc.1 <null> ldloc.0 <null> call System.Diagnostics.Process[] System.Diagnostics.Process::GetProcessesByName(System.String) call System.Diagnostics.Process System.Linq.Enumerable::FirstOrDefault<System.Diagnostics.Process>(System.Collections.Generic.IEnumerable`1<System.Diagnostics.Process>) stloc.2 <null> ldloc.2 <null> brtrue IL_003E: ldc.i4 2035711 ldloc.0 <null> call System.String <Module>::JETuvkqTZw() call System.String System.String::Concat(System.String,System.String) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String) stloc.2 <null> ldc.i4 1500 call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.i4 2035711 ldc.i4.0 <null> ldloc.2 <null> callvirt System.Int32 System.Diagnostics.Process::get_Id() call System.IntPtr zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::VYfOVCdbDINDNQwaAKaLVvsvsQdrhRQAGLgyxCKv(System.UInt32,System.Boolean,System.Int32) stloc.3 <null> ldloc.3 <null> ldsfld System.IntPtr System.IntPtr::Zero call System.Boolean System.IntPtr::op_Equality(System.IntPtr,System.IntPtr) brfalse IL_0065: ldloc.3 leave IL_00A4: ret ldloc.3 <null> ldloc.1 <null> call System.IntPtr zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::hIEWSEqKbRpYWAJLKbGwzRTdiJKLDJFdoIRPMswj(System.IntPtr,System.Byte[]) stloc.s V_4 ldloc.s V_4 ldsfld System.IntPtr System.IntPtr::Zero call System.Boolean System.IntPtr::op_Equality(System.IntPtr,System.IntPtr) brfalse IL_0084: ldloc.3 leave IL_00A4: ret ldloc.3 <null> ldloc.1 <null> ldloc.s V_4 call System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::AJcDIVOuuTfNdHJpOANiUFgrlmKnIUZrFwVPOpvn(System.IntPtr,System.Byte[],System.IntPtr) ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave IL_00A4: ret pop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave IL_00A4: ret ret <null>

Module Name

BhVayAL

Full Name

BhVayAL

EntryPoint

System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::ngTOHfWyBiDRHpgjiKRKUbHzCZoRtkgAUbpTZcRq(System.String[])

Scope Name

BhVayAL

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

WindowsFormsApp1

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

8

Main Method

System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::ngTOHfWyBiDRHpgjiKRKUbHzCZoRtkgAUbpTZcRq(System.String[])

Main IL Instruction Count

50

Main IL

call System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::zSKTbuWpBYWnFGamytmIQeerccWFZmkgTBlcrNyh() call System.String <Module>::LMzmJOoFaa() stloc.0 <null> call System.Byte[] zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::cZpunTVobduFPjAuNsRYxqpoOQteuXUKUeFQOKei() stloc.1 <null> ldloc.0 <null> call System.Diagnostics.Process[] System.Diagnostics.Process::GetProcessesByName(System.String) call System.Diagnostics.Process System.Linq.Enumerable::FirstOrDefault<System.Diagnostics.Process>(System.Collections.Generic.IEnumerable`1<System.Diagnostics.Process>) stloc.2 <null> ldloc.2 <null> brtrue IL_003E: ldc.i4 2035711 ldloc.0 <null> call System.String <Module>::JETuvkqTZw() call System.String System.String::Concat(System.String,System.String) call System.Diagnostics.Process System.Diagnostics.Process::Start(System.String) stloc.2 <null> ldc.i4 1500 call System.Void System.Threading.Thread::Sleep(System.Int32) ldc.i4 2035711 ldc.i4.0 <null> ldloc.2 <null> callvirt System.Int32 System.Diagnostics.Process::get_Id() call System.IntPtr zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::VYfOVCdbDINDNQwaAKaLVvsvsQdrhRQAGLgyxCKv(System.UInt32,System.Boolean,System.Int32) stloc.3 <null> ldloc.3 <null> ldsfld System.IntPtr System.IntPtr::Zero call System.Boolean System.IntPtr::op_Equality(System.IntPtr,System.IntPtr) brfalse IL_0065: ldloc.3 leave IL_00A4: ret ldloc.3 <null> ldloc.1 <null> call System.IntPtr zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::hIEWSEqKbRpYWAJLKbGwzRTdiJKLDJFdoIRPMswj(System.IntPtr,System.Byte[]) stloc.s V_4 ldloc.s V_4 ldsfld System.IntPtr System.IntPtr::Zero call System.Boolean System.IntPtr::op_Equality(System.IntPtr,System.IntPtr) brfalse IL_0084: ldloc.3 leave IL_00A4: ret ldloc.3 <null> ldloc.1 <null> ldloc.s V_4 call System.Void zEAsONqPEEgAHHfPxytYsQetuXmMIXcGCqTmWVdI::AJcDIVOuuTfNdHJpOANiUFgrlmKnIUZrFwVPOpvn(System.IntPtr,System.Byte[],System.IntPtr) ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave IL_00A4: ret pop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave IL_00A4: ret ret <null>

6c203fef991986c1325ba64600c1f47e (136.19 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙