Suspicious
Suspect

784b133746547af60241c34f2baa4221

PE Executable
MD5: 784b133746547af60241c34f2baa4221
Size: 1.28 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 784b133746547af60241c34f2baa4221
Sha1 dd88dbac58538178c6beac4be15112664e3db50d
Sha256 634ee94b03b59107d28e593cdf46b0d2d6347d44440b8a011952154c470775e5
Sha384 13a9579827c338adc01ded0de8ad2a80e4b09960bad203d9c0947db980022640a469deed004a61db5dbab2d08bd9adfe
Sha512 b82fb89ab4188dfe7169f03c2d89a22d6b23cdab586d1aa57628120b0c717dc082df796126a55fb74a16b75858702618ed1162d557d6cb7e48dd4f5ff882da51
SSDeep 24576:fcL2MhgqlgQMFpl9xeA7hQzi5IO79L4qK:flMeqlg9Fpl9JQzmH9Li
TLSH 9645E04113E89F58F8BFAB3C5478042047F6FC56AE35D7BE2E5858AD2872B80DA51723
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
Tafinobix.kbfida.levi
Cz8k0RiaGao.Resources.resources
f19dd51d1c90a6.Resources.resources
94ec6f660
[NBF]root.Data
94ec6f661
[NBF]root.Data
94ec6f6610
[NBF]root.Data
94ec6f6611
[NBF]root.Data
94ec6f6612
[NBF]root.Data
94ec6f6613
[NBF]root.Data
94ec6f6614
[NBF]root.Data
94ec6f6615
[NBF]root.Data
94ec6f6616
[NBF]root.Data
94ec6f6617
[NBF]root.Data
94ec6f6618
[NBF]root.Data
94ec6f6619
[NBF]root.Data
94ec6f662
[NBF]root.Data
94ec6f6620
[NBF]root.Data
94ec6f6621
[NBF]root.Data
94ec6f6622
[NBF]root.Data
94ec6f6623
[NBF]root.Data
94ec6f6624
[NBF]root.Data
94ec6f663
[NBF]root.Data
94ec6f664
[NBF]root.Data
94ec6f665
[NBF]root.Data
94ec6f666
[NBF]root.Data
94ec6f667
[NBF]root.Data
94ec6f668
[NBF]root.Data
94ec6f669
[NBF]root.Data
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Module Name
Cz8k0RiaGao
Full Name
Cz8k0RiaGao
EntryPoint
System.Void Cz8k0RiaGao.2Tkiw::zB_2z()
Scope Name
Cz8k0RiaGao
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Cz8k0RiaGao
Assembly Version
6.17.25.265
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1399
Main Method
System.Void Cz8k0RiaGao.2Tkiw::zB_2z()
Main IL Instruction Count
41
Main IL
nop <null>
newobj System.Void System.Windows.Forms.Form::.ctor()
stloc.0 <null>
ldc.r8 25
stloc.1 <null>
ldloc.1 <null>
ldc.r8 1
sub <null>
call System.Double System.Math::Round(System.Double)
conv.ovf.i4 <null>
ldc.i4.1 <null>
add.ovf <null>
newarr System.Object
stloc.2 <null>
ldstr kbfida.levi
stloc.3 <null>
ldloc.3 <null>
call System.Object Cz8k0RiaGao.RenoLedger.Lpa1c0gZ/jr4WDoz.9mcSkJ::To2xpCx59wjWg(System.String)
call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object)
stloc.s V_4
ldloc.s V_4
call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object)
call System.Object Cz8k0RiaGao.2Tkiw::3Psdp6nYK(System.Object)
call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object)
stloc.s V_5
ldloc.2 <null>
ldloc.1 <null>
ldc.r8 1
sub <null>
call System.Double System.Math::Round(System.Double)
conv.ovf.i4 <null>
ldloc.s V_5
call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object)
stelem.ref <null>
ldloc.2 <null>
ldloc.1 <null>
call System.Double System.Math::Round(System.Double)
conv.ovf.i4 <null>
call System.Void Cz8k0RiaGao.2Tkiw::1Hrkj2cR0bCz(System.Object[],System.Int32)
nop <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
Cz8k0RiaGao
Full Name
Cz8k0RiaGao
EntryPoint
System.Void Cz8k0RiaGao.2Tkiw::zB_2z()
Scope Name
Cz8k0RiaGao
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Cz8k0RiaGao
Assembly Version
6.17.25.265
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1399
Main Method
System.Void Cz8k0RiaGao.2Tkiw::zB_2z()
Main IL Instruction Count
41
Main IL
nop <null>
newobj System.Void System.Windows.Forms.Form::.ctor()
stloc.0 <null>
ldc.r8 25
stloc.1 <null>
ldloc.1 <null>
ldc.r8 1
sub <null>
call System.Double System.Math::Round(System.Double)
conv.ovf.i4 <null>
ldc.i4.1 <null>
add.ovf <null>
newarr System.Object
stloc.2 <null>
ldstr kbfida.levi
stloc.3 <null>
ldloc.3 <null>
call System.Object Cz8k0RiaGao.RenoLedger.Lpa1c0gZ/jr4WDoz.9mcSkJ::To2xpCx59wjWg(System.String)
call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object)
stloc.s V_4
ldloc.s V_4
call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object)
call System.Object Cz8k0RiaGao.2Tkiw::3Psdp6nYK(System.Object)
call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object)
stloc.s V_5
ldloc.2 <null>
ldloc.1 <null>
ldc.r8 1
sub <null>
call System.Double System.Math::Round(System.Double)
conv.ovf.i4 <null>
ldloc.s V_5
call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object)
stelem.ref <null>
ldloc.2 <null>
ldloc.1 <null>
call System.Double System.Math::Round(System.Double)
conv.ovf.i4 <null>
call System.Void Cz8k0RiaGao.2Tkiw::1Hrkj2cR0bCz(System.Object[],System.Int32)
nop <null>
ret <null>
.Net Resources
Tafinobix.kbfida.levi
Cz8k0RiaGao.Resources.resources
f19dd51d1c90a6.Resources.resources
94ec6f660
[NBF]root.Data
94ec6f661
[NBF]root.Data
94ec6f6610
[NBF]root.Data
94ec6f6611
[NBF]root.Data
94ec6f6612
[NBF]root.Data
94ec6f6613
[NBF]root.Data
94ec6f6614
[NBF]root.Data
94ec6f6615
[NBF]root.Data
94ec6f6616
[NBF]root.Data
94ec6f6617
[NBF]root.Data
94ec6f6618
[NBF]root.Data
94ec6f6619
[NBF]root.Data
94ec6f662
[NBF]root.Data
94ec6f6620
[NBF]root.Data
94ec6f6621
[NBF]root.Data
94ec6f6622
[NBF]root.Data
94ec6f6623
[NBF]root.Data
94ec6f6624
[NBF]root.Data
94ec6f663
[NBF]root.Data
94ec6f664
[NBF]root.Data
94ec6f665
[NBF]root.Data
94ec6f666
[NBF]root.Data
94ec6f667
[NBF]root.Data
94ec6f668
[NBF]root.Data
94ec6f669
[NBF]root.Data
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙