Suspicious
Suspect

PE Executable
MD5: 7fdb8886eb8b149af6bb26d6dafdfac8
Size: 20.48 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7fdb8886eb8b149af6bb26d6dafdfac8
Sha1 71aa40b3e6e290b0cdc2f28be6f3368ba4fd8985
Sha256 4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a
Sha384 36cf073d67f4bbef6292ce70a1341547c9d0767ea87482758540ba2984d78e44030d609fc202fba9fc68743f23500b48
Sha512 797c1ebcba605e4e48b4935a70b4b7ebfd0703ae48cb63a1f787ac9a8eff2db9cad744cc03ee63ebabfdaccd7fcdfda183d1a45797729fac81b78afa30463933
SSDeep 384:jVz3Jq+XSUJb+JTHPSl3C53yrITlSgCLlyLsrCStgzQs0Vzo:jVjJDXSUYT063ykz+UEyQs0q
TLSH B592E848AB546669D27E067C2DDE8320CBB2430B7453DB3B2EE66CE90C112D9D151EFB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
뽜.뽜.resources
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
WindowsFormsApp13.exe
Full Name
WindowsFormsApp13.exe
EntryPoint
System.Void 뽜.뾀::뽜(System.String[])
Scope Name
WindowsFormsApp13.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WindowsFormsApp13
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
1
Main Method
System.Void 뽜.뾀::뽜(System.String[])
Main IL Instruction Count
53
Main IL
nop <null>
ldarg.0 <null>
ldlen <null>
brfalse.s IL_0014: ldc.i4.0
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뽜()
call System.Boolean System.String::op_Equality(System.String,System.String)
br.s IL_0015: stloc.0
ldc.i4.0 <null>
stloc.0 <null>
ldloc.0 <null>
brfalse.s IL_002B: nop
nop <null>
call System.IntPtr 뽜.뾀::뾀()
stloc.1 <null>
ldloc.1 <null>
ldc.i4.0 <null>
call System.Boolean 뽜.뾀::뽜(System.IntPtr,System.Int32)
pop <null>
nop <null>
br.s IL_004C: call System.Void 뽜.뾀::뽜()
nop <null>
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뾏()
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뾀()
call System.String System.Windows.Forms.Application::get_ExecutablePath()
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뼺()
call System.String System.String::Concat(System.String,System.String,System.String)
call System.Void 뽜.뾀::뽜(System.String,System.String)
nop <null>
nop <null>
call System.Void 뽜.뾀::뽜()
nop <null>
ldnull <null>
ldftn System.Void 뽜.뾀::뾏()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stsfld System.Threading.Thread 뽜.뾀::뾍
ldsfld System.Threading.Thread 뽜.뾀::뾍
ldc.i4.0 <null>
callvirt System.Void System.Threading.Thread::SetApartmentState(System.Threading.ApartmentState)
nop <null>
ldsfld System.Threading.Thread 뽜.뾀::뾍
ldc.i4.1 <null>
callvirt System.Void System.Threading.Thread::set_IsBackground(System.Boolean)
nop <null>
ldsfld System.Threading.Thread 뽜.뾀::뾍
callvirt System.Void System.Threading.Thread::Start()
nop <null>
call System.Void System.Windows.Forms.Application::Run()
nop <null>
ret <null>
Module Name
WindowsFormsApp13.exe
Full Name
WindowsFormsApp13.exe
EntryPoint
System.Void 뽜.뾀::뽜(System.String[])
Scope Name
WindowsFormsApp13.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WindowsFormsApp13
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
1
Main Method
System.Void 뽜.뾀::뽜(System.String[])
Main IL Instruction Count
53
Main IL
nop <null>
ldarg.0 <null>
ldlen <null>
brfalse.s IL_0014: ldc.i4.0
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뽜()
call System.Boolean System.String::op_Equality(System.String,System.String)
br.s IL_0015: stloc.0
ldc.i4.0 <null>
stloc.0 <null>
ldloc.0 <null>
brfalse.s IL_002B: nop
nop <null>
call System.IntPtr 뽜.뾀::뾀()
stloc.1 <null>
ldloc.1 <null>
ldc.i4.0 <null>
call System.Boolean 뽜.뾀::뽜(System.IntPtr,System.Int32)
pop <null>
nop <null>
br.s IL_004C: call System.Void 뽜.뾀::뽜()
nop <null>
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뾏()
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뾀()
call System.String System.Windows.Forms.Application::get_ExecutablePath()
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뼺()
call System.String System.String::Concat(System.String,System.String,System.String)
call System.Void 뽜.뾀::뽜(System.String,System.String)
nop <null>
nop <null>
call System.Void 뽜.뾀::뽜()
nop <null>
ldnull <null>
ldftn System.Void 뽜.뾀::뾏()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stsfld System.Threading.Thread 뽜.뾀::뾍
ldsfld System.Threading.Thread 뽜.뾀::뾍
ldc.i4.0 <null>
callvirt System.Void System.Threading.Thread::SetApartmentState(System.Threading.ApartmentState)
nop <null>
ldsfld System.Threading.Thread 뽜.뾀::뾍
ldc.i4.1 <null>
callvirt System.Void System.Threading.Thread::set_IsBackground(System.Boolean)
nop <null>
ldsfld System.Threading.Thread 뽜.뾀::뾍
callvirt System.Void System.Threading.Thread::Start()
nop <null>
call System.Void System.Windows.Forms.Application::Run()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
뽜.뽜.resources
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙