Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: 98b741acd352a8a48fcc8f7c94b0502e
Size: 1.16 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 98b741acd352a8a48fcc8f7c94b0502e
Sha1 58585889116f7889fcbdfe79bfdaa659aaf78e81
Sha256 238441c6a05dd55e6cee3b33c991a8d91302c9e687e4607f2b33ca74dc850ea5
Sha384 a0cf4964ad6431369cd9978ad10560f5aab5e35a6f87d5389a232b2da2f9966c2b279364810aa181995b949167279ca9
Sha512 75ef5c37e470630d6c6084821149ead58c036167a59366c1bc82387ffbd2b61ced046c90e0553e1c9552b61f250daee3462a1e531411c4595498965177bcd28c
SSDeep 12288:WuHN6JaLZokGOuXJxNB3+MLi6bvar5vknJlZelegsUPr3AMMSUqf1GFzO21KObA5:WglLZoNOYwMW9UwljzAE30L1KObz4L
TLSH 5135E0060EC32B94D1594F7CD2A610A877F0D55B9212E76F2FED42F0EEA7B4AC906463
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
xSm4Fg.Resources.resources
xSm4Fg.g.resources
30866e83b6aec0.Resources.resources
1f16a5340
[NBF]root.Data
1f16a5341
[NBF]root.Data
1f16a53410
[NBF]root.Data
1f16a53411
[NBF]root.Data
1f16a53412
[NBF]root.Data
1f16a53413
[NBF]root.Data
1f16a53414
[NBF]root.Data
1f16a53415
[NBF]root.Data
1f16a53416
[NBF]root.Data
1f16a53417
[NBF]root.Data
1f16a53418
[NBF]root.Data
1f16a53419
[NBF]root.Data
1f16a5342
[NBF]root.Data
1f16a53420
[NBF]root.Data
1f16a53421
[NBF]root.Data
1f16a53422
[NBF]root.Data
1f16a53423
[NBF]root.Data
1f16a53424
[NBF]root.Data
1f16a53425
[NBF]root.Data
1f16a53426
[NBF]root.Data
1f16a53427
[NBF]root.Data
1f16a53428
[NBF]root.Data
1f16a53429
[NBF]root.Data
1f16a5343
[NBF]root.Data
1f16a53430
[NBF]root.Data
1f16a53431
[NBF]root.Data
1f16a53432
[NBF]root.Data
1f16a53433
[NBF]root.Data
1f16a53434
[NBF]root.Data
1f16a53435
[NBF]root.Data
1f16a53436
[NBF]root.Data
1f16a53437
[NBF]root.Data
1f16a5344
[NBF]root.Data
1f16a5345
[NBF]root.Data
1f16a5346
[NBF]root.Data
1f16a5347
[NBF]root.Data
1f16a5348
[NBF]root.Data
1f16a5349
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
xSm4Fg
Full Name
xSm4Fg
EntryPoint
System.Void Pr7pqAe68_GgzH.Qae1pt5D/pz3Ne5D.3pwEBf4w::qDp01sk()
Scope Name
xSm4Fg
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xSm4Fg
Assembly Version
6.17.24.263
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void Pr7pqAe68_GgzH.Qae1pt5D/pz3Ne5D.3pwEBf4w::qDp01sk()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void Bzp29sXqbDj.5wtWcY3_aeC::.ctor()
stloc.0 <null>
ret <null>
ldtoken System.Void Pr7pqAe68_GgzH.Qae1pt5D/pz3Ne5D.3pwEBf4w::qDp01sk()
pop <null>
ret <null>
Module Name
xSm4Fg
Full Name
xSm4Fg
EntryPoint
System.Void Pr7pqAe68_GgzH.Qae1pt5D/pz3Ne5D.3pwEBf4w::qDp01sk()
Scope Name
xSm4Fg
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xSm4Fg
Assembly Version
6.17.24.263
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void Pr7pqAe68_GgzH.Qae1pt5D/pz3Ne5D.3pwEBf4w::qDp01sk()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void Bzp29sXqbDj.5wtWcY3_aeC::.ctor()
stloc.0 <null>
ret <null>
ldtoken System.Void Pr7pqAe68_GgzH.Qae1pt5D/pz3Ne5D.3pwEBf4w::qDp01sk()
pop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙