Malicious
Malicious

PE Executable
MD5: 7c19202f05ab44a0fd1f800eff8020c8
Size: 1.45 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7c19202f05ab44a0fd1f800eff8020c8
Sha1 e8a16677fde136470f8074e1929068ee8e4b7311
Sha256 a597c2e3591fa1db03f00323ebfd51039f207af1325b6c41a90b7b5ec5a5ac4e
Sha384 2323068c8ef3a1151c413047e7b5bcd9c882bcb1821fd4a9290047beb7c2d15bb9865fac741a7be66b2c812c66d1634d
Sha512 0098324eb4fba33fdf2e9314bf469242b20fa4c74af2c53c2d9b19dbcd737280fc16e77a3479aeefcbe09adc9b4e63598c66f64b672581efd265460cbf25b7e1
SSDeep 24576:4iD3Bc1I91e4YeuXcfzD2i0/P/EgFPulXYtdDkLf6dywzPCUcTo:rMIHfJwXEERgfcPCzT
TLSH 19657B027E44CE11F0191333C2EF458897B5A8517AA6E32B7DBA376E25123A77C1D9CB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
XXrq5pguSNnXtIKgdf.nohcBGBqrEcOHiZCPd
lssgs72Zm5hYpwVpca.gOxDtrI5xwExks9OOe
Name Value
Module Name
IcwbDXvta
Full Name
IcwbDXvta
EntryPoint
System.Void QnTbUkfIuFI2PR6FIQr.jbqiL0f1isJO5CLt0IX::hfOYufDkvn()
Scope Name
IcwbDXvta
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
clHUiBjwAudEWdGoZ
Assembly Version
6.9.7.3
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void QnTbUkfIuFI2PR6FIQr.jbqiL0f1isJO5CLt0IX::hfOYufDkvn()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void K90oZoYetXMcFGfNMk3.TbQi8AYts7M9sTWfmMa::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object QnTbUkfIuFI2PR6FIQr.jbqiL0f1isJO5CLt0IX::Dj5YpPPRAN
callvirt System.Void TocvqKftgLvtGcfGMk2.yiUTWffCoRyZ4P1bxxH::UVnxiPVQSG()
nop <null>
ret <null>
Module Name
IcwbDXvta
Full Name
IcwbDXvta
EntryPoint
System.Void QnTbUkfIuFI2PR6FIQr.jbqiL0f1isJO5CLt0IX::hfOYufDkvn()
Scope Name
IcwbDXvta
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
clHUiBjwAudEWdGoZ
Assembly Version
6.9.7.3
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void QnTbUkfIuFI2PR6FIQr.jbqiL0f1isJO5CLt0IX::hfOYufDkvn()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void K90oZoYetXMcFGfNMk3.TbQi8AYts7M9sTWfmMa::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object QnTbUkfIuFI2PR6FIQr.jbqiL0f1isJO5CLt0IX::Dj5YpPPRAN
callvirt System.Void TocvqKftgLvtGcfGMk2.yiUTWffCoRyZ4P1bxxH::UVnxiPVQSG()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
XXrq5pguSNnXtIKgdf.nohcBGBqrEcOHiZCPd
lssgs72Zm5hYpwVpca.gOxDtrI5xwExks9OOe
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙