Suspicious
Suspect

8efb64799745bbffe81b82d55f488e5c

PE Executable
|
MD5: 8efb64799745bbffe81b82d55f488e5c
|
Size: 689.66 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
8efb64799745bbffe81b82d55f488e5c
Sha1
d6ab6d809435cb2c074467fb5e2b21b25a30ac16
Sha256
6d5de61b4ceade81ec1a26f9d3c156344f0588efd20f35ed16ad9e50646c932a
Sha384
04bd3cbe2b2af81f1069c902b79441d227b96493450d614bf189b7a7c5d03d34d7db4c88c9d24fc2be93665e76e3b0ce
Sha512
cba0e59b7ca34e6142685dd13c493c0a4b98427ea239ab02234a680189c97dbe2da6e56310fa17ce31136116ee5486b928f832c25f564d6b7eff704a8699267f
SSDeep
12288:YuF18yYNfdDoaCkYjULe/2DuVFs2vanzu5H/zkiGLi:Br0DoavYZOaO2vanG/zA
TLSH
4EE4BF055D4A6B99D57F0FB8C0220894F7F0D643A396E79F3FEC10F45AA3B84CA0A956

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Mbm1tx4BwF.Resources.resources
Mbm1tx4BwF.g.resources
26a03e7a7d0cbc.Resources.resources
222bc9fd0
[NBF]root.Data
222bc9fd1
[NBF]root.Data
222bc9fd2
[NBF]root.Data
222bc9fd3
[NBF]root.Data
222bc9fd4
[NBF]root.Data
222bc9fd5
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Mbm1tx4BwF

Full Name

Mbm1tx4BwF

EntryPoint

System.Void cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7::ff5FEok1()

Scope Name

Mbm1tx4BwF

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Mbm1tx4BwF

Assembly Version

19.16.46.251

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

0

Main Method

System.Void cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7::ff5FEok1()

Main IL Instruction Count

203

Main IL

ldc.i4.1 <null> stloc.s V_18 ldloc.s V_18 switch dnlib.DotNet.Emit.Instruction[] nop <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> ldc.i4.s 25 stloc.2 <null> ldc.i4 411085 box System.Int32 stloc.3 <null> ldsfld System.String cFc9P4pys_.os2R1DtjFyc0r::Rb6e1 stloc.s V_4 ldc.i4.7 <null> stloc.s V_18 br.s IL_0003: ldloc.s V_18 ldloc.s V_4 call System.String cFc9P4pys_.os2R1DtjFyc0r/1AfkJf4.4opSX5dq6::yYr13axQtP2b(System.String) stloc.s V_5 ldloc.s V_5 call System.Byte[] Zjq3mN.wy0N7Yqkxw1Sg::Rgy4jB9s7mWeg(System.String) ldloc.3 <null> call System.Int32 Microsoft.VisualBasic.CompilerServices.Conversions::ToInteger(System.Object) call System.Object Zjq3mN.wy0N7Yqkxw1Sg/Gjb17W_gp9Qt.3ykTeKs46js/6QicbsW5J.iSy20isEZg5w::Dqj5p6Crnd7(System.Byte[],System.Int32) ldnull <null> nop <null> ldc.i8 15 ldc.i4 510372757 ldc.i4.1 <null> call System.String Ggq24nFpc.Kgp0e3B/8Bfqr1iS.nJp6wo1FB::Kx2x0Poaf3(System.Int64,System.Int32,System.Int32) ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_6 ldc.i4.s 9 stloc.s V_18 br IL_0003: ldloc.s V_18 ldc.i4.3 <null> stloc.s V_7 ldc.i4.7 <null> stloc.0 <null> nop <null> ldloc.s V_7 ldc.i4.3 <null> beq.s IL_00B5: ldc.i4.5 ldc.i4.6 <null> stloc.s V_18 br IL_0003: ldloc.s V_18 ldc.i4.5 <null> br.s IL_00AE: stloc.s V_18 ldc.i4.8 <null> stloc.s V_18 br IL_0003: ldloc.s V_18 nop <null> ldloc.s V_6 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_8 ldc.i4.8 <null> stloc.s V_18 br IL_0003: ldloc.s V_18 nop <null> ldc.i4.s 9 stloc.0 <null> ldtoken System.Reflection.Assembly call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) stloc.s V_9 ldloc.s V_9 callvirt System.Reflection.MethodInfo[] System.Type::GetMethods() ldsfld System.Func`2<System.Reflection.MethodInfo,System.Boolean> cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::Kd6w8ce brfalse.s IL_00F7: ldsfld cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::4Hojw5PwgA ldsfld System.Func`2<System.Reflection.MethodInfo,System.Boolean> cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::Kd6w8ce br.s IL_010D: call System.Collections.Generic.IEnumerable`1<System.Reflection.MethodInfo> System.Linq.Enumerable::Where<System.Reflection.MethodInfo>(System.Collections.Generic.IEnumerable`1<System.Reflection.MethodInfo>,System.Func`2<System.Reflection.MethodInfo,System.Boolean>) ldsfld cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::4Hojw5PwgA ldftn System.Boolean cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::3qtPeq(System.Reflection.MethodInfo) newobj System.Void System.Func`2<System.Reflection.MethodInfo,System.Boolean>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Func`2<System.Reflection.MethodInfo,System.Boolean> cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::Kd6w8ce call System.Collections.Generic.IEnumerable`1<System.Reflection.MethodInfo> System.Linq.Enumerable::Where<System.Reflection.MethodInfo>(System.Collections.Generic.IEnumerable`1<System.Reflection.MethodInfo>,System.Func`2<System.Reflection.MethodInfo,System.Boolean>) call System.Reflection.MethodInfo[] System.Linq.Enumerable::ToArray<System.Reflection.MethodInfo>(System.Collections.Generic.IEnumerable`1<System.Reflection.MethodInfo>) stloc.s V_10 ldloc.s V_10 stloc.s V_11 ldc.i4.0 <null> stloc.s V_12 br IL_0232: ldloc.s V_12 ldloc.s V_11 ldloc.s V_12 ldelem.ref <null> stloc.s V_13 br.s IL_012E: br.s IL_0130 br.s IL_0130: ldc.i4.0 ldc.i4.0 <null> stloc.s V_20 ldloc.s V_20 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0154: nop nop <null> ldloc.s V_13 ldnull <null> ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldloc.s V_8 stelem.ref <null> callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_14 ldc.i4.4 <null> stloc.s V_20 br.s IL_0133: ldloc.s V_20 ldloc.s V_14 ldnull <null> nop <null> ldc.i4 1115889363 ldnull <null> ldc.i4.0 <null> call System.String Ggq24nFpc.Kgp0e3B/iKw0t4.3yzQanN86wqK::Mg5e8Wyb(System.Int32,System.Reflection.Assembly,System.Int32) ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldc.i4.s 25 box System.Int32 stelem.ref <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateIndexGet(System.Object,System.Object[],System.String[]) ldnull <null> nop <null> ldc.i4.8 <null> ldc.i4 507198917 ldc.i4.s 23 call System.String Ggq24nFpc.Kgp0e3B/iKw0t4.3yzQanN86wqK/bCf71ejQaw.1Qsor7_DFpn6r::bb4RsWm9g3(System.Int32,System.Int32,System.Byte) ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldc.i4.0 <null> box System.Int32 stelem.ref <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateIndexGet(System.Object,System.Object[],System.String[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Object cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7::K_k41gPeJ3(System.Object) pop <null> leave.s IL_0248: ldc.i4.4 br.s IL_01E9: br.s IL_01EB br.s IL_01EB: dup dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_15 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_01FB: br.s IL_01FD br.s IL_01FD: ldc.i4.1 ldc.i4.1 <null> stloc.s V_22 ldloc.s V_22 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0225: nop nop <null> nop <null> ldloc.s V_12 ldc.i4.1 <null> add.ovf <null> stloc.s V_12 ldc.i4.0 <null> stloc.s V_22 br.s IL_0200: ldloc.s V_22 ldloc.s V_12 ldloc.s V_11 ldlen <null> conv.i4 <null> clt <null> stloc.s V_16 ldloc.s V_16 brtrue IL_0125: ldloc.s V_11 ldc.i4.4 <null> stloc.s V_22 br.s IL_0200: ldloc.s V_22 ldc.i4.4 <null> stloc.0 <null> ret <null> ldtoken System.Void cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7::ff5FEok1() pop <null> ret <null>

Module Name

Mbm1tx4BwF

Full Name

Mbm1tx4BwF

EntryPoint

System.Void cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7::ff5FEok1()

Scope Name

Mbm1tx4BwF

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Mbm1tx4BwF

Assembly Version

19.16.46.251

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

0

Main Method

System.Void cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7::ff5FEok1()

Main IL Instruction Count

203

Main IL

ldc.i4.1 <null> stloc.s V_18 ldloc.s V_18 switch dnlib.DotNet.Emit.Instruction[] nop <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> ldc.i4.s 25 stloc.2 <null> ldc.i4 411085 box System.Int32 stloc.3 <null> ldsfld System.String cFc9P4pys_.os2R1DtjFyc0r::Rb6e1 stloc.s V_4 ldc.i4.7 <null> stloc.s V_18 br.s IL_0003: ldloc.s V_18 ldloc.s V_4 call System.String cFc9P4pys_.os2R1DtjFyc0r/1AfkJf4.4opSX5dq6::yYr13axQtP2b(System.String) stloc.s V_5 ldloc.s V_5 call System.Byte[] Zjq3mN.wy0N7Yqkxw1Sg::Rgy4jB9s7mWeg(System.String) ldloc.3 <null> call System.Int32 Microsoft.VisualBasic.CompilerServices.Conversions::ToInteger(System.Object) call System.Object Zjq3mN.wy0N7Yqkxw1Sg/Gjb17W_gp9Qt.3ykTeKs46js/6QicbsW5J.iSy20isEZg5w::Dqj5p6Crnd7(System.Byte[],System.Int32) ldnull <null> nop <null> ldc.i8 15 ldc.i4 510372757 ldc.i4.1 <null> call System.String Ggq24nFpc.Kgp0e3B/8Bfqr1iS.nJp6wo1FB::Kx2x0Poaf3(System.Int64,System.Int32,System.Int32) ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_6 ldc.i4.s 9 stloc.s V_18 br IL_0003: ldloc.s V_18 ldc.i4.3 <null> stloc.s V_7 ldc.i4.7 <null> stloc.0 <null> nop <null> ldloc.s V_7 ldc.i4.3 <null> beq.s IL_00B5: ldc.i4.5 ldc.i4.6 <null> stloc.s V_18 br IL_0003: ldloc.s V_18 ldc.i4.5 <null> br.s IL_00AE: stloc.s V_18 ldc.i4.8 <null> stloc.s V_18 br IL_0003: ldloc.s V_18 nop <null> ldloc.s V_6 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_8 ldc.i4.8 <null> stloc.s V_18 br IL_0003: ldloc.s V_18 nop <null> ldc.i4.s 9 stloc.0 <null> ldtoken System.Reflection.Assembly call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) stloc.s V_9 ldloc.s V_9 callvirt System.Reflection.MethodInfo[] System.Type::GetMethods() ldsfld System.Func`2<System.Reflection.MethodInfo,System.Boolean> cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::Kd6w8ce brfalse.s IL_00F7: ldsfld cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::4Hojw5PwgA ldsfld System.Func`2<System.Reflection.MethodInfo,System.Boolean> cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::Kd6w8ce br.s IL_010D: call System.Collections.Generic.IEnumerable`1<System.Reflection.MethodInfo> System.Linq.Enumerable::Where<System.Reflection.MethodInfo>(System.Collections.Generic.IEnumerable`1<System.Reflection.MethodInfo>,System.Func`2<System.Reflection.MethodInfo,System.Boolean>) ldsfld cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::4Hojw5PwgA ldftn System.Boolean cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::3qtPeq(System.Reflection.MethodInfo) newobj System.Void System.Func`2<System.Reflection.MethodInfo,System.Boolean>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Func`2<System.Reflection.MethodInfo,System.Boolean> cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7/Pbq4qd7E.To1xd6EfbGr2ed::Kd6w8ce call System.Collections.Generic.IEnumerable`1<System.Reflection.MethodInfo> System.Linq.Enumerable::Where<System.Reflection.MethodInfo>(System.Collections.Generic.IEnumerable`1<System.Reflection.MethodInfo>,System.Func`2<System.Reflection.MethodInfo,System.Boolean>) call System.Reflection.MethodInfo[] System.Linq.Enumerable::ToArray<System.Reflection.MethodInfo>(System.Collections.Generic.IEnumerable`1<System.Reflection.MethodInfo>) stloc.s V_10 ldloc.s V_10 stloc.s V_11 ldc.i4.0 <null> stloc.s V_12 br IL_0232: ldloc.s V_12 ldloc.s V_11 ldloc.s V_12 ldelem.ref <null> stloc.s V_13 br.s IL_012E: br.s IL_0130 br.s IL_0130: ldc.i4.0 ldc.i4.0 <null> stloc.s V_20 ldloc.s V_20 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0154: nop nop <null> ldloc.s V_13 ldnull <null> ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldloc.s V_8 stelem.ref <null> callvirt System.Object System.Reflection.MethodBase::Invoke(System.Object,System.Object[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_14 ldc.i4.4 <null> stloc.s V_20 br.s IL_0133: ldloc.s V_20 ldloc.s V_14 ldnull <null> nop <null> ldc.i4 1115889363 ldnull <null> ldc.i4.0 <null> call System.String Ggq24nFpc.Kgp0e3B/iKw0t4.3yzQanN86wqK::Mg5e8Wyb(System.Int32,System.Reflection.Assembly,System.Int32) ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldc.i4.s 25 box System.Int32 stelem.ref <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateIndexGet(System.Object,System.Object[],System.String[]) ldnull <null> nop <null> ldc.i4.8 <null> ldc.i4 507198917 ldc.i4.s 23 call System.String Ggq24nFpc.Kgp0e3B/iKw0t4.3yzQanN86wqK/bCf71ejQaw.1Qsor7_DFpn6r::bb4RsWm9g3(System.Int32,System.Int32,System.Byte) ldc.i4.0 <null> newarr System.Object ldnull <null> ldnull <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) ldc.i4.1 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldc.i4.0 <null> box System.Int32 stelem.ref <null> ldnull <null> call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateIndexGet(System.Object,System.Object[],System.String[]) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Object cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7::K_k41gPeJ3(System.Object) pop <null> leave.s IL_0248: ldc.i4.4 br.s IL_01E9: br.s IL_01EB br.s IL_01EB: dup dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_15 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_01FB: br.s IL_01FD br.s IL_01FD: ldc.i4.1 ldc.i4.1 <null> stloc.s V_22 ldloc.s V_22 switch dnlib.DotNet.Emit.Instruction[] br.s IL_0225: nop nop <null> nop <null> ldloc.s V_12 ldc.i4.1 <null> add.ovf <null> stloc.s V_12 ldc.i4.0 <null> stloc.s V_22 br.s IL_0200: ldloc.s V_22 ldloc.s V_12 ldloc.s V_11 ldlen <null> conv.i4 <null> clt <null> stloc.s V_16 ldloc.s V_16 brtrue IL_0125: ldloc.s V_11 ldc.i4.4 <null> stloc.s V_22 br.s IL_0200: ldloc.s V_22 ldc.i4.4 <null> stloc.0 <null> ret <null> ldtoken System.Void cFc9P4pys_.os2R1DtjFyc0r/Mjt63Gc.fx2C7::ff5FEok1() pop <null> ret <null>

8efb64799745bbffe81b82d55f488e5c (689.66 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙