Malicious
Malicious

7a6e1f72127803df7ac870e1f95b95d6

PE Executable
MD5: 7a6e1f72127803df7ac870e1f95b95d6
Size: 239.62 KB
application/x-dosexec
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
7a6e1f72127803df7ac870e1f95b95d6
Sha1
a859bb10a8826c53875eaf9c45594a4af5511ef1
Sha256
110753d68aee76f03897dbf55014fe5f7af90fca0b0110ba4139ca6b4185ec2a
Sha384
121cea0461a2d8b768c7f6c51f8db24e117ec699294f01f5bb3d4fe8898ada53269f038d615a9b817126f169a13bd261
Sha512
900b2647b299c7c418f255a1b8734e03cfb17771779008caf621bb49ad645342bf9084f878d87449c052d59ea0d6c70ebb2b146e1027a89048c65d4edea2410e
SSDeep
3072:kCppimSVMrdtm6/d7Uz5t0i/bMqOub254Ssko2F:hppimSVMrPXd7UFN/oqOub9/k/
TLSH
A5340E037E88EB15E1A83E3B92EF6C2413B2B0C71633D20B6F49AF6614516525D7E72D

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

ppeUUGCd5c2

Full Name

ppeUUGCd5c2

EntryPoint

System.Void Njsy.TIih8WcH::yjh4dmUYGh()

Scope Name

ppeUUGCd5c2

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

7dfcfdf2-d881-49c9-a39e-708aca656f85

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

1049

Main Method

System.Void Njsy.TIih8WcH::yjh4dmUYGh()

Main IL Instruction Count

62

Main IL

ldc.i4 0 stloc V_0 br IL_00EF: br IL_000E nop <null> ldloc V_0 ldc.i4 4 ceq <null> brfalse IL_002D: nop call System.Void System.Windows.Forms.Application::Run() ldc.i4 5 stloc V_0 nop <null> ldloc V_0 ldc.i4 2 ceq <null> brfalse IL_007B: nop call System.Net.Security.RemoteCertificateValidationCallback System.Net.ServicePointManager::get_ServerCertificateValidationCallback() ldsfld System.Net.Security.RemoteCertificateValidationCallback Njsy.TIih8WcH::CS$<>9__CachedAnonymousMethodDelegate1 brtrue IL_005E: ldsfld System.Net.Security.RemoteCertificateValidationCallback Njsy.TIih8WcH::CS$<>9__CachedAnonymousMethodDelegate1 ldnull <null> ldftn System.Boolean Njsy.TIih8WcH::XKC(System.Object,System.Security.Cryptography.X509Certificates.X509Certificate,System.Security.Cryptography.X509Certificates.X509Chain,System.Net.Security.SslPolicyErrors) newobj System.Void System.Net.Security.RemoteCertificateValidationCallback::.ctor(System.Object,System.IntPtr) stsfld System.Net.Security.RemoteCertificateValidationCallback Njsy.TIih8WcH::CS$<>9__CachedAnonymousMethodDelegate1 ldsfld System.Net.Security.RemoteCertificateValidationCallback Njsy.TIih8WcH::CS$<>9__CachedAnonymousMethodDelegate1 call System.Delegate System.Delegate::Combine(System.Delegate,System.Delegate) castclass System.Net.Security.RemoteCertificateValidationCallback call System.Void System.Net.ServicePointManager::set_ServerCertificateValidationCallback(System.Net.Security.RemoteCertificateValidationCallback) ldc.i4 3 stloc V_0 nop <null> ldloc V_0 ldc.i4 1 ceq <null> brfalse IL_009F: nop ldc.i4 4080 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4 2 stloc V_0 nop <null> ldloc V_0 ldc.i4 3 ceq <null> brfalse IL_00BE: nop call System.Void 0XPR8ZCx9X9.SnaQAinb::5OqijTeslm() ldc.i4 4 stloc V_0 nop <null> ldloc V_0 ldc.i4 0 ceq <null> brfalse IL_00D9: nop nop <null> ldc.i4 1 stloc V_0 nop <null> ldloc V_0 ldc.i4 5 ceq <null> brfalse IL_00EF: br IL_000E br IL_00F4: ret br IL_000E: nop ret <null>

Module Name

ppeUUGCd5c2

Full Name

ppeUUGCd5c2

EntryPoint

System.Void Njsy.TIih8WcH::yjh4dmUYGh()

Scope Name

ppeUUGCd5c2

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

7dfcfdf2-d881-49c9-a39e-708aca656f85

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

1049

Main Method

System.Void Njsy.TIih8WcH::yjh4dmUYGh()

Main IL Instruction Count

62

Main IL

ldc.i4 0 stloc V_0 br IL_00EF: br IL_000E nop <null> ldloc V_0 ldc.i4 4 ceq <null> brfalse IL_002D: nop call System.Void System.Windows.Forms.Application::Run() ldc.i4 5 stloc V_0 nop <null> ldloc V_0 ldc.i4 2 ceq <null> brfalse IL_007B: nop call System.Net.Security.RemoteCertificateValidationCallback System.Net.ServicePointManager::get_ServerCertificateValidationCallback() ldsfld System.Net.Security.RemoteCertificateValidationCallback Njsy.TIih8WcH::CS$<>9__CachedAnonymousMethodDelegate1 brtrue IL_005E: ldsfld System.Net.Security.RemoteCertificateValidationCallback Njsy.TIih8WcH::CS$<>9__CachedAnonymousMethodDelegate1 ldnull <null> ldftn System.Boolean Njsy.TIih8WcH::XKC(System.Object,System.Security.Cryptography.X509Certificates.X509Certificate,System.Security.Cryptography.X509Certificates.X509Chain,System.Net.Security.SslPolicyErrors) newobj System.Void System.Net.Security.RemoteCertificateValidationCallback::.ctor(System.Object,System.IntPtr) stsfld System.Net.Security.RemoteCertificateValidationCallback Njsy.TIih8WcH::CS$<>9__CachedAnonymousMethodDelegate1 ldsfld System.Net.Security.RemoteCertificateValidationCallback Njsy.TIih8WcH::CS$<>9__CachedAnonymousMethodDelegate1 call System.Delegate System.Delegate::Combine(System.Delegate,System.Delegate) castclass System.Net.Security.RemoteCertificateValidationCallback call System.Void System.Net.ServicePointManager::set_ServerCertificateValidationCallback(System.Net.Security.RemoteCertificateValidationCallback) ldc.i4 3 stloc V_0 nop <null> ldloc V_0 ldc.i4 1 ceq <null> brfalse IL_009F: nop ldc.i4 4080 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4 2 stloc V_0 nop <null> ldloc V_0 ldc.i4 3 ceq <null> brfalse IL_00BE: nop call System.Void 0XPR8ZCx9X9.SnaQAinb::5OqijTeslm() ldc.i4 4 stloc V_0 nop <null> ldloc V_0 ldc.i4 0 ceq <null> brfalse IL_00D9: nop nop <null> ldc.i4 1 stloc V_0 nop <null> ldloc V_0 ldc.i4 5 ceq <null> brfalse IL_00EF: br IL_000E br IL_00F4: ret br IL_000E: nop ret <null>

7a6e1f72127803df7ac870e1f95b95d6 (239.62 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙