Suspicious
Suspect

9e2ee4799282249194b3ae8e7070617d

PE Executable
|
MD5: 9e2ee4799282249194b3ae8e7070617d
|
Size: 1.48 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
9e2ee4799282249194b3ae8e7070617d
Sha1
78ad86a57790ae3b60c2ea4ec87f34e919426f50
Sha256
031dbb2abab32fa35f27c03c86cb1533dfd46562ab91594f0ae0d4296ee91638
Sha384
b3f3c4de614665b819a63cb8617fe4cfd9bd58e47d5c45be1fab8bfb9a896dc92c21cafc17269ed9a918cc288afbeb9a
Sha512
39d622bbd4012843eebf958586513aaa16cd42ef8b557a6f0677f013012774668bed6d7780a9e47b91bff6a289da8ffeb18d5224546051b0b559eb98042ddeec
SSDeep
24576:65mJzIMSuUS/jLnPhozXKEDiqqaPEMyznEa36Sz3emGkmzaieWxv9:6Uz1jizXKEuWYnjzupa+v9
TLSH
CB65F19607C51EA7C2FFC736D8E26621CB78E551E3CBE34E158658655C0BBBA8C00A1F

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
{95617c8f-41c7-4796-896b-6f6cd014111d}
Informations
Name
Value
Module Name

Sedjsi.exe

Full Name

Sedjsi.exe

EntryPoint

System.Void .::()

Scope Name

Sedjsi.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Sedjsi

Assembly Version

1.0.4808.22535

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

780

Main Method

System.Void .::()

Main IL Instruction Count

21

Main IL

ldc.i4.1 <null> brfalse.s IL_000F: ldsfld ./ ./:: ldc.i4.0 <null> brtrue.s IL_000F: ldsfld ./ ./:: ldsfld System.Action`1<System.IO.MemoryStream> ./:: dup <null> brtrue.s IL_0025: br.s IL_002E pop <null> ldsfld ./ ./:: ldftn System.Void ./::(System.IO.MemoryStream) newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action`1<System.IO.MemoryStream> ./:: br.s IL_002E: call System.Void .::(System.Action`1<System.IO.MemoryStream>) ldc.i4.0 <null> brtrue.s IL_0000: ldc.i4.1 ldc.i4.0 <null> brtrue.s IL_000F: ldsfld ./ ./:: ret <null> call System.Void .::(System.Action`1<System.IO.MemoryStream>) br.s IL_0027: ldc.i4.0

Module Name

Sedjsi.exe

Full Name

Sedjsi.exe

EntryPoint

System.Void .::()

Scope Name

Sedjsi.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Sedjsi

Assembly Version

1.0.4808.22535

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

780

Main Method

System.Void .::()

Main IL Instruction Count

21

Main IL

ldc.i4.1 <null> brfalse.s IL_000F: ldsfld ./ ./:: ldc.i4.0 <null> brtrue.s IL_000F: ldsfld ./ ./:: ldsfld System.Action`1<System.IO.MemoryStream> ./:: dup <null> brtrue.s IL_0025: br.s IL_002E pop <null> ldsfld ./ ./:: ldftn System.Void ./::(System.IO.MemoryStream) newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Action`1<System.IO.MemoryStream> ./:: br.s IL_002E: call System.Void .::(System.Action`1<System.IO.MemoryStream>) ldc.i4.0 <null> brtrue.s IL_0000: ldc.i4.1 ldc.i4.0 <null> brtrue.s IL_000F: ldsfld ./ ./:: ret <null> call System.Void .::(System.Action`1<System.IO.MemoryStream>) br.s IL_0027: ldc.i4.0

9e2ee4799282249194b3ae8e7070617d (1.48 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
{95617c8f-41c7-4796-896b-6f6cd014111d}
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙