Suspicious
Suspect

91ed5854d998ca39fa3ea6fbf3acdc79

Share on LinkedIn
Print
PE Executable
MD5: 91ed5854d998ca39fa3ea6fbf3acdc79
Size: 791.55 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 91ed5854d998ca39fa3ea6fbf3acdc79
Sha1 8afe4b242ce8afd079f14a60af91f7eebfed702c
Sha256 d2d35b1008ab18a196bf68887081208b475a1a70a74ef2ee8da7fe065cc4ad09
Sha384 86f6f81873dea3ed9c139f766801eeba99819a4e8f2778edfa333f59281d1b393b17847e0ef956355a449c9995a83082
Sha512 a3086e7b979906575f5bfd71c771872c28e295f38e19f460eadff5b9a2e9348677b3ea0d71d897896c841db22bc9baf2e8af278a233872102613474e073d9097
SSDeep 12288:ty0so+PNkkiSmhbxkjC92g54RNIlmz4wyaFApOl3rUu4uvG1+ZqZ/jdjgl7ewqpr:VChYbxoq2g54Io/A8lbvGvHu7e7J
TLSH 20F4010DFE76EE55C95C0B7196431DB442A68D83F562F76F2C8178C21A76B88908F2CB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
hASt.exe
Full Name
hASt.exe
EntryPoint
System.Void DamassaProject.Program::Main()
Scope Name
hASt.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hASt
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void DamassaProject.Program::Main()
Main IL Instruction Count
27
Main IL
ldsfld System.Int32[] DamassaProject.fmrCadastro::Ⴓ
stloc.2 <null>
ldc.i4.0 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void DamassaProject.Repositories.AdminstradorReposirory::Ⴍ()
ldc.i4 746
ldc.i4 724
call System.Void DamassaProject.fmrAdministrador::Ⴍ(System.Char,System.Int16)
ldc.i4.0 <null>
ldc.i4 338
ldc.i4 283
call System.Void DamassaProject.Properties.Resources::Ⴐ(System.Boolean,System.Int16,System.Char)
ldloc.2 <null>
ldc.i4 441
ldelem.i4 <null>
ldc.i4 51421
sub <null>
stloc.1 <null>
br.s IL_0008: ldloc.1
newobj System.Void DamassaProject.fmrListarUsuario::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void DamassaProject.Program::Main()
pop <null>
ret <null>
Module Name
hASt.exe
Full Name
hASt.exe
EntryPoint
System.Void DamassaProject.Program::Main()
Scope Name
hASt.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
hASt
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void DamassaProject.Program::Main()
Main IL Instruction Count
27
Main IL
ldsfld System.Int32[] DamassaProject.fmrCadastro::Ⴓ
stloc.2 <null>
ldc.i4.0 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void DamassaProject.Repositories.AdminstradorReposirory::Ⴍ()
ldc.i4 746
ldc.i4 724
call System.Void DamassaProject.fmrAdministrador::Ⴍ(System.Char,System.Int16)
ldc.i4.0 <null>
ldc.i4 338
ldc.i4 283
call System.Void DamassaProject.Properties.Resources::Ⴐ(System.Boolean,System.Int16,System.Char)
ldloc.2 <null>
ldc.i4 441
ldelem.i4 <null>
ldc.i4 51421
sub <null>
stloc.1 <null>
br.s IL_0008: ldloc.1
newobj System.Void DamassaProject.fmrListarUsuario::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
ldtoken System.Void DamassaProject.Program::Main()
pop <null>
ret <null>
Embedded Resources UNKNWOWN
0huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙