Suspicious
Suspect

8d56427cb65aed3bdb35fea1238583cd

PE Executable
MD5: 8d56427cb65aed3bdb35fea1238583cd
Size: 3.6 MB
application/x-dosexec
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very low

Hash
Hash Value
MD5
8d56427cb65aed3bdb35fea1238583cd
Sha1
a3c2c2594559e8a8391aad134762e6dfcd60f420
Sha256
f67f2fa47b7335ecfbfc059f1639f688321457a7a847c8d9f5156f35ac5ce814
Sha384
f19adb474a5b1897c98ac124f740dd44496ae5f3043d9ad4c646c64a7f28ce2f377997b3db825784631fdcee71f38ff5
Sha512
7a7e1453fb60db8f9f610b256ab30e6a680b7bd083e04fcc2267463b3bcfa4cbfff513370cd75921e5fd76e60ab26728f165bffb0339132ee81cb490dc5a777b
SSDeep
49152:LwL2OIUMouq2/WD8WVbTR8AMFcWJGZCVqmmVH6fURyxRum4cT+0V5:LWIf9qzDhVytFTJGZG9rfURy1
TLSH
30F5AF48A7359E06CEC2AB35F4F747112B61E438C097A343871EB6796A363D56F83293

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
UPolyX 0.3 -> delikon
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Cyrljddr.Qjnmrg.resources
Cyrljddr.Properties.Resources.resources
Nybixr
Limilabs.Ftp.FTP.Client.ResponseCodes.txt
Limilabs.Ftp.InternalLicensing.RevokedGuids.txt
Limilabs.Ftp.FTP.Licensing.Installer.ico
Limilabs.Ftp.InternalLicensing.pkt
Limilabs.Ftp.InternalLicensing.pk
Informations
Name
Value
Module Name

Vvmrg.exe

Full Name

Vvmrg.exe

EntryPoint

System.Void Cyrljddr.Kquhylsq::Main()

Scope Name

Vvmrg.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Vvmrg

Assembly Version

1.0.3990.5844

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1146

Main Method

System.Void Cyrljddr.Kquhylsq::Main()

Main IL Instruction Count

17

Main IL

ldsfld System.Threading.ThreadStart Cyrljddr.Kquhylsq/<>c::<>9__0_0 dup <null> brtrue IL_0022: newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) pop <null> ldsfld Cyrljddr.Kquhylsq/<>c Cyrljddr.Kquhylsq/<>c::<>9 ldftn System.Void Cyrljddr.Kquhylsq/<>c::<Main>b__0_0() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Threading.ThreadStart Cyrljddr.Kquhylsq/<>c::<>9__0_0 newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) dup <null> ldc.i4.0 <null> callvirt System.Void System.Threading.Thread::set_IsBackground(System.Boolean) callvirt System.Void System.Threading.Thread::Start() ldc.i4 1000 call System.Void System.Threading.Thread::Sleep(System.Int32) br.s IL_0033: ldc.i4 1000

Module Name

Vvmrg.exe

Full Name

Vvmrg.exe

EntryPoint

System.Void Cyrljddr.Kquhylsq::Main()

Scope Name

Vvmrg.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Vvmrg

Assembly Version

1.0.3990.5844

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1146

Main Method

System.Void Cyrljddr.Kquhylsq::Main()

Main IL Instruction Count

17

Main IL

ldsfld System.Threading.ThreadStart Cyrljddr.Kquhylsq/<>c::<>9__0_0 dup <null> brtrue IL_0022: newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) pop <null> ldsfld Cyrljddr.Kquhylsq/<>c Cyrljddr.Kquhylsq/<>c::<>9 ldftn System.Void Cyrljddr.Kquhylsq/<>c::<Main>b__0_0() newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Threading.ThreadStart Cyrljddr.Kquhylsq/<>c::<>9__0_0 newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart) dup <null> ldc.i4.0 <null> callvirt System.Void System.Threading.Thread::set_IsBackground(System.Boolean) callvirt System.Void System.Threading.Thread::Start() ldc.i4 1000 call System.Void System.Threading.Thread::Sleep(System.Int32) br.s IL_0033: ldc.i4 1000

Artefacts
Name
Value
Embedded Resources

7

Suspicious Type Names (1-2 chars)

0

8d56427cb65aed3bdb35fea1238583cd (3.6 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙