Malicious
Malicious

8e65d142051e11b9e5366f5f4ed88d9e

PE Executable
|
MD5: 8e65d142051e11b9e5366f5f4ed88d9e
|
Size: 323.58 KB
|
application/x-dosexec


Print
Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
8e65d142051e11b9e5366f5f4ed88d9e
Sha1
1774e43902d92c75f2a6101deda937c9c0117eda
Sha256
6f25b64efa6c3595eccd87c8c3a1f5265950b3f64bdcde882338ad9d84712f02
Sha384
7d7f5e3703c6b32084706ebcaafb0e41200c7bb48a0d4e749b25eaff1d00aeaf47e08e2f720193ba3ffedc9670d41961
Sha512
ea6addbf5cf3c335c32af06a3c466550485b6a06bc97e3bacfcc3c46af77f14258c3ef38b68031b72f863a4191e00d09b949f4eb06bcbec9f817502a1d39ec7a
SSDeep
6144:HiVp6DGx4Y9lPFa5GIykgZ8SV/rwcj65BzLO2L4eK+:HiP6M4qi5GI9gZ88r16/e2Q
TLSH
6164CF07A3E64E10E6EA9F34D8F7612403F2F7562B33EB9F2A5401992D53761CE107A6

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
WMfXD5GcX1MgIGZZMb.kXVrRgk44JKN3CsPgv
14643896-d282-46e0-a97c-9fe2bc06da74.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

jdkg

Full Name

jdkg

EntryPoint

System.Void rVb6FO2.lvb::Lsa4cP9K2Wa()

Scope Name

jdkg

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

14643896-d282-46e0-a97c-9fe2bc06da74

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

461d39c4a423da0b

Target Framework

<null>

Total Strings

69

Main Method

System.Void rVb6FO2.lvb::Lsa4cP9K2Wa()

Main IL Instruction Count

65

Main IL

br.s IL_0004: ldc.i4 0 pop <null> ldc.i4.0 <null> ldc.i4 0 stloc V_0 br IL_00F3: br IL_0012 nop <null> ldloc V_0 ldc.i4 1 ceq <null> brfalse IL_0036: nop ldc.i4 4080 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4 2 stloc V_0 nop <null> ldloc V_0 ldc.i4 4 ceq <null> brfalse IL_0055: nop call System.Void System.Windows.Forms.Application::Run() ldc.i4 5 stloc V_0 nop <null> ldloc V_0 ldc.i4 3 ceq <null> brfalse IL_0074: nop call System.Void QI3.KsQeXu::vEmlKd2X() ldc.i4 4 stloc V_0 nop <null> ldloc V_0 ldc.i4 2 ceq <null> brfalse IL_00C2: nop call System.Net.Security.RemoteCertificateValidationCallback System.Net.ServicePointManager::get_ServerCertificateValidationCallback() ldsfld System.Net.Security.RemoteCertificateValidationCallback rVb6FO2.lvb::CS$<>9__CachedAnonymousMethodDelegate1 brtrue IL_00A5: ldsfld System.Net.Security.RemoteCertificateValidationCallback rVb6FO2.lvb::CS$<>9__CachedAnonymousMethodDelegate1 ldnull <null> ldftn System.Boolean rVb6FO2.lvb::quLfINWl4k6(System.Object,System.Security.Cryptography.X509Certificates.X509Certificate,System.Security.Cryptography.X509Certificates.X509Chain,System.Net.Security.SslPolicyErrors) newobj System.Void System.Net.Security.RemoteCertificateValidationCallback::.ctor(System.Object,System.IntPtr) stsfld System.Net.Security.RemoteCertificateValidationCallback rVb6FO2.lvb::CS$<>9__CachedAnonymousMethodDelegate1 ldsfld System.Net.Security.RemoteCertificateValidationCallback rVb6FO2.lvb::CS$<>9__CachedAnonymousMethodDelegate1 call System.Delegate System.Delegate::Combine(System.Delegate,System.Delegate) castclass System.Net.Security.RemoteCertificateValidationCallback call System.Void System.Net.ServicePointManager::set_ServerCertificateValidationCallback(System.Net.Security.RemoteCertificateValidationCallback) ldc.i4 3 stloc V_0 nop <null> ldloc V_0 ldc.i4 0 ceq <null> brfalse IL_00DD: nop nop <null> ldc.i4 1 stloc V_0 nop <null> ldloc V_0 ldc.i4 5 ceq <null> brfalse IL_00F3: br IL_0012 br IL_00F8: ret br IL_0012: nop ret <null>

Module Name

jdkg

Full Name

jdkg

EntryPoint

System.Void rVb6FO2.lvb::Lsa4cP9K2Wa()

Scope Name

jdkg

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

14643896-d282-46e0-a97c-9fe2bc06da74

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

461d39c4a423da0b

Target Framework

<null>

Total Strings

69

Main Method

System.Void rVb6FO2.lvb::Lsa4cP9K2Wa()

Main IL Instruction Count

65

Main IL

br.s IL_0004: ldc.i4 0 pop <null> ldc.i4.0 <null> ldc.i4 0 stloc V_0 br IL_00F3: br IL_0012 nop <null> ldloc V_0 ldc.i4 1 ceq <null> brfalse IL_0036: nop ldc.i4 4080 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4 2 stloc V_0 nop <null> ldloc V_0 ldc.i4 4 ceq <null> brfalse IL_0055: nop call System.Void System.Windows.Forms.Application::Run() ldc.i4 5 stloc V_0 nop <null> ldloc V_0 ldc.i4 3 ceq <null> brfalse IL_0074: nop call System.Void QI3.KsQeXu::vEmlKd2X() ldc.i4 4 stloc V_0 nop <null> ldloc V_0 ldc.i4 2 ceq <null> brfalse IL_00C2: nop call System.Net.Security.RemoteCertificateValidationCallback System.Net.ServicePointManager::get_ServerCertificateValidationCallback() ldsfld System.Net.Security.RemoteCertificateValidationCallback rVb6FO2.lvb::CS$<>9__CachedAnonymousMethodDelegate1 brtrue IL_00A5: ldsfld System.Net.Security.RemoteCertificateValidationCallback rVb6FO2.lvb::CS$<>9__CachedAnonymousMethodDelegate1 ldnull <null> ldftn System.Boolean rVb6FO2.lvb::quLfINWl4k6(System.Object,System.Security.Cryptography.X509Certificates.X509Certificate,System.Security.Cryptography.X509Certificates.X509Chain,System.Net.Security.SslPolicyErrors) newobj System.Void System.Net.Security.RemoteCertificateValidationCallback::.ctor(System.Object,System.IntPtr) stsfld System.Net.Security.RemoteCertificateValidationCallback rVb6FO2.lvb::CS$<>9__CachedAnonymousMethodDelegate1 ldsfld System.Net.Security.RemoteCertificateValidationCallback rVb6FO2.lvb::CS$<>9__CachedAnonymousMethodDelegate1 call System.Delegate System.Delegate::Combine(System.Delegate,System.Delegate) castclass System.Net.Security.RemoteCertificateValidationCallback call System.Void System.Net.ServicePointManager::set_ServerCertificateValidationCallback(System.Net.Security.RemoteCertificateValidationCallback) ldc.i4 3 stloc V_0 nop <null> ldloc V_0 ldc.i4 0 ceq <null> brfalse IL_00DD: nop nop <null> ldc.i4 1 stloc V_0 nop <null> ldloc V_0 ldc.i4 5 ceq <null> brfalse IL_00F3: br IL_0012 br IL_00F8: ret br IL_0012: nop ret <null>

8e65d142051e11b9e5366f5f4ed88d9e (323.58 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙