Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 7fdb8886eb8b149af6bb26d6dafdfac8
Size: 20.48 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7fdb8886eb8b149af6bb26d6dafdfac8
Sha1 71aa40b3e6e290b0cdc2f28be6f3368ba4fd8985
Sha256 4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a
Sha384 36cf073d67f4bbef6292ce70a1341547c9d0767ea87482758540ba2984d78e44030d609fc202fba9fc68743f23500b48
Sha512 797c1ebcba605e4e48b4935a70b4b7ebfd0703ae48cb63a1f787ac9a8eff2db9cad744cc03ee63ebabfdaccd7fcdfda183d1a45797729fac81b78afa30463933
SSDeep 384:jVz3Jq+XSUJb+JTHPSl3C53yrITlSgCLlyLsrCStgzQs0Vzo:jVjJDXSUYT063ykz+UEyQs0q
TLSH B592E848AB546669D27E067C2DDE8320CBB2430B7453DB3B2EE66CE90C112D9D151EFB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
뽜.뽜.resources
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
WindowsFormsApp13.exe
Full Name
WindowsFormsApp13.exe
EntryPoint
System.Void 뽜.뾀::뽜(System.String[])
Scope Name
WindowsFormsApp13.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WindowsFormsApp13
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
1
Main Method
System.Void 뽜.뾀::뽜(System.String[])
Main IL Instruction Count
53
Main IL
nop <null>
ldarg.0 <null>
ldlen <null>
brfalse.s IL_0014: ldc.i4.0
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뽜()
call System.Boolean System.String::op_Equality(System.String,System.String)
br.s IL_0015: stloc.0
ldc.i4.0 <null>
stloc.0 <null>
ldloc.0 <null>
brfalse.s IL_002B: nop
nop <null>
call System.IntPtr 뽜.뾀::뾀()
stloc.1 <null>
ldloc.1 <null>
ldc.i4.0 <null>
call System.Boolean 뽜.뾀::뽜(System.IntPtr,System.Int32)
pop <null>
nop <null>
br.s IL_004C: call System.Void 뽜.뾀::뽜()
nop <null>
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뾏()
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뾀()
call System.String System.Windows.Forms.Application::get_ExecutablePath()
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뼺()
call System.String System.String::Concat(System.String,System.String,System.String)
call System.Void 뽜.뾀::뽜(System.String,System.String)
nop <null>
nop <null>
call System.Void 뽜.뾀::뽜()
nop <null>
ldnull <null>
ldftn System.Void 뽜.뾀::뾏()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stsfld System.Threading.Thread 뽜.뾀::뾍
ldsfld System.Threading.Thread 뽜.뾀::뾍
ldc.i4.0 <null>
callvirt System.Void System.Threading.Thread::SetApartmentState(System.Threading.ApartmentState)
nop <null>
ldsfld System.Threading.Thread 뽜.뾀::뾍
ldc.i4.1 <null>
callvirt System.Void System.Threading.Thread::set_IsBackground(System.Boolean)
nop <null>
ldsfld System.Threading.Thread 뽜.뾀::뾍
callvirt System.Void System.Threading.Thread::Start()
nop <null>
call System.Void System.Windows.Forms.Application::Run()
nop <null>
ret <null>
Module Name
WindowsFormsApp13.exe
Full Name
WindowsFormsApp13.exe
EntryPoint
System.Void 뽜.뾀::뽜(System.String[])
Scope Name
WindowsFormsApp13.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
WindowsFormsApp13
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
1
Main Method
System.Void 뽜.뾀::뽜(System.String[])
Main IL Instruction Count
53
Main IL
nop <null>
ldarg.0 <null>
ldlen <null>
brfalse.s IL_0014: ldc.i4.0
ldarg.0 <null>
ldc.i4.0 <null>
ldelem.ref <null>
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뽜()
call System.Boolean System.String::op_Equality(System.String,System.String)
br.s IL_0015: stloc.0
ldc.i4.0 <null>
stloc.0 <null>
ldloc.0 <null>
brfalse.s IL_002B: nop
nop <null>
call System.IntPtr 뽜.뾀::뾀()
stloc.1 <null>
ldloc.1 <null>
ldc.i4.0 <null>
call System.Boolean 뽜.뾀::뽜(System.IntPtr,System.Int32)
pop <null>
nop <null>
br.s IL_004C: call System.Void 뽜.뾀::뽜()
nop <null>
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뾏()
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뾀()
call System.String System.Windows.Forms.Application::get_ExecutablePath()
call System.String <PrivateImplementationDetails>{27C367A2-55AE-4D51-AF26-7C4B24D9C775}.4D96598A-7077-4789-9765-0F46E1FAE7B5::뼺()
call System.String System.String::Concat(System.String,System.String,System.String)
call System.Void 뽜.뾀::뽜(System.String,System.String)
nop <null>
nop <null>
call System.Void 뽜.뾀::뽜()
nop <null>
ldnull <null>
ldftn System.Void 뽜.뾀::뾏()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stsfld System.Threading.Thread 뽜.뾀::뾍
ldsfld System.Threading.Thread 뽜.뾀::뾍
ldc.i4.0 <null>
callvirt System.Void System.Threading.Thread::SetApartmentState(System.Threading.ApartmentState)
nop <null>
ldsfld System.Threading.Thread 뽜.뾀::뾍
ldc.i4.1 <null>
callvirt System.Void System.Threading.Thread::set_IsBackground(System.Boolean)
nop <null>
ldsfld System.Threading.Thread 뽜.뾀::뾍
callvirt System.Void System.Threading.Thread::Start()
nop <null>
call System.Void System.Windows.Forms.Application::Run()
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙