Suspicious
Suspect

91ed5854d998ca39fa3ea6fbf3acdc79

PE Executable
MD5: 91ed5854d998ca39fa3ea6fbf3acdc79
Size: 791.55 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 91ed5854d998ca39fa3ea6fbf3acdc79
Sha1 8afe4b242ce8afd079f14a60af91f7eebfed702c
Sha256 d2d35b1008ab18a196bf68887081208b475a1a70a74ef2ee8da7fe065cc4ad09
Sha384 86f6f81873dea3ed9c139f766801eeba99819a4e8f2778edfa333f59281d1b393b17847e0ef956355a449c9995a83082
Sha512 a3086e7b979906575f5bfd71c771872c28e295f38e19f460eadff5b9a2e9348677b3ea0d71d897896c841db22bc9baf2e8af278a233872102613474e073d9097
SSDeep 12288:ty0so+PNkkiSmhbxkjC92g54RNIlmz4wyaFApOl3rUu4uvG1+ZqZ/jdjgl7ewqpr:VChYbxoq2g54Io/A8lbvGvHu7e7J
TLSH 20F4010DFE76EE55C95C0B7196431DB442A68D83F562F76F2C8178C21A76B88908F2CB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
hASt.exe
Full Name
hASt.exe
EntryPoint
System.Void DamassaProject.Program::Main()
Scope Name
hASt.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hASt
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void DamassaProject.Program::Main()
Main IL Instruction Count
27
Main IL
ldsfld System.Int32[] DamassaProject.fmrCadastro::Ⴓ
stloc.2 <null>
ldc.i4.0 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void DamassaProject.Repositories.AdminstradorReposirory::Ⴍ()
ldc.i4 746
ldc.i4 724
call System.Void DamassaProject.fmrAdministrador::Ⴍ(System.Char,System.Int16)
ldc.i4.0 <null>
ldc.i4 338
ldc.i4 283
call System.Void DamassaProject.Properties.Resources::Ⴐ(System.Boolean,System.Int16,System.Char)
ldloc.2 <null>
ldc.i4 441
ldelem.i4 <null>
ldc.i4 51421
sub <null>
stloc.1 <null>
br.s IL_0008: ldloc.1
newobj System.Void DamassaProject.fmrListarUsuario::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void DamassaProject.Program::Main()
pop <null>
ret <null>
Module Name
hASt.exe
Full Name
hASt.exe
EntryPoint
System.Void DamassaProject.Program::Main()
Scope Name
hASt.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hASt
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void DamassaProject.Program::Main()
Main IL Instruction Count
27
Main IL
ldsfld System.Int32[] DamassaProject.fmrCadastro::Ⴓ
stloc.2 <null>
ldc.i4.0 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void DamassaProject.Repositories.AdminstradorReposirory::Ⴍ()
ldc.i4 746
ldc.i4 724
call System.Void DamassaProject.fmrAdministrador::Ⴍ(System.Char,System.Int16)
ldc.i4.0 <null>
ldc.i4 338
ldc.i4 283
call System.Void DamassaProject.Properties.Resources::Ⴐ(System.Boolean,System.Int16,System.Char)
ldloc.2 <null>
ldc.i4 441
ldelem.i4 <null>
ldc.i4 51421
sub <null>
stloc.1 <null>
br.s IL_0008: ldloc.1
newobj System.Void DamassaProject.fmrListarUsuario::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void DamassaProject.Program::Main()
pop <null>
ret <null>
Embedded Resources UNKNWOWN
0huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWN
0huhuhuhu
91ed5854d998ca39fa3ea6fbf3acdc79
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
91ed5854d998ca39fa3ea6fbf3acdc79
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙