Suspicious
Suspect

9fc714794e26467a9f9054ffc8de3801

PE Executable
|
MD5: 9fc714794e26467a9f9054ffc8de3801
|
Size: 395.78 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
9fc714794e26467a9f9054ffc8de3801
Sha1
1015194c05e1f34f0e485a40b98fd589dded7582
Sha256
3d72779314a937fb668feda17e3e527505c21b1e2d2fa0e731795c47d3f98fd6
Sha384
85d0ba7c852d37fe23c9163b13b55b4c3982b30d10487d7ff8d96d0d3b8eda30a01e3f9bdc6cc8a81238dab1397bf522
Sha512
7af5b4804641e7244e71db0429f7b23ce447c6f6c10eeb1273247595650d6f7e91d7f92e9461f5286243722bb88197501d49aab42ed9723209149b932cfb3704
SSDeep
6144:z3nqygehRXAZ57wph5VCclVxNlf8YJNyDJOUrnqlw4F8y+HuJD6oGGMFFSE0SIC0:4h
TLSH
3B84BAEA8C6ADC03DBED25BAE8F054B1937018DF9473443CEDE6253FD0E119972A9621

PeID

.NET executable
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
ID:000B
ID:0
ID:000C
ID:0
ID:000D
ID:0
ID:000E
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ILRepack.List
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Veeznweerb

Full Name

Veeznweerb

EntryPoint

System.Void Hjgtmizvy.Ropuamcre::Main()

Scope Name

Veeznweerb

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Veeznweerb

Assembly Version

1.0.5804.22496

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

15

Main Method

System.Void Hjgtmizvy.Ropuamcre::Main()

Main IL Instruction Count

42

Main IL

newobj System.Void Hjgtmizvy.Ghmrj::.ctor() stloc.0 <null> newobj System.Void Hjgtmizvy.Neknrcz::.ctor() stloc.1 <null> newobj System.Void Hjgtmizvy.Xfazcuq::.ctor() stloc.2 <null> newobj System.Void Hjgtmizvy.Hdpaizs::.ctor() stloc.3 <null> ldloc.1 <null> ldloc.2 <null> ldloc.3 <null> newobj System.Void Hjgtmizvy.Wbyyw::.ctor(Hjgtmizvy.Neknrcz,Hjgtmizvy.Xfazcuq,Hjgtmizvy.Hdpaizs) stloc.s V_4 ldloc.0 <null> ldloc.s V_4 ldftn System.Void Hjgtmizvy.Wbyyw::Yaipqqvr(System.Object,Hjgtmizvy.Heecfxmlwu) newobj System.Void System.EventHandler`1<Hjgtmizvy.Heecfxmlwu>::.ctor(System.Object,System.IntPtr) callvirt System.Void Hjgtmizvy.Ghmrj::add_DownloadCompleted(System.EventHandler`1<Hjgtmizvy.Heecfxmlwu>) ldloc.1 <null> ldloc.s V_4 ldftn System.Void Hjgtmizvy.Wbyyw::Tbhjnu(System.Object,Hjgtmizvy.Ggijucy) newobj System.Void System.EventHandler`1<Hjgtmizvy.Ggijucy>::.ctor(System.Object,System.IntPtr) callvirt System.Void Hjgtmizvy.Neknrcz::add_DecryptionCompleted(System.EventHandler`1<Hjgtmizvy.Ggijucy>) ldloc.2 <null> ldloc.s V_4 ldftn System.Void Hjgtmizvy.Wbyyw::Qvnenensm(System.Object,Hjgtmizvy.Aeeie) newobj System.Void System.EventHandler`1<Hjgtmizvy.Aeeie>::.ctor(System.Object,System.IntPtr) callvirt System.Void Hjgtmizvy.Xfazcuq::add_LoadCompleted(System.EventHandler`1<Hjgtmizvy.Aeeie>) ldloc.3 <null> ldloc.s V_4 ldftn System.Void Hjgtmizvy.Wbyyw::Bawgwvgq(System.Object,Hjgtmizvy.Lxkbdgiqezp) newobj System.Void System.EventHandler`1<Hjgtmizvy.Lxkbdgiqezp>::.ctor(System.Object,System.IntPtr) callvirt System.Void Hjgtmizvy.Hdpaizs::add_InvocationCompleted(System.EventHandler`1<Hjgtmizvy.Lxkbdgiqezp>) ldloc.0 <null> callvirt System.Void Hjgtmizvy.Ghmrj::Ihwkrgljdh() leave.s IL_0082: ret ldloc.s V_4 brfalse.s IL_0081: endfinally ldloc.s V_4 callvirt System.Void System.IDisposable::Dispose() endfinally <null> ret <null>

Module Name

Veeznweerb

Full Name

Veeznweerb

EntryPoint

System.Void Hjgtmizvy.Ropuamcre::Main()

Scope Name

Veeznweerb

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Veeznweerb

Assembly Version

1.0.5804.22496

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

15

Main Method

System.Void Hjgtmizvy.Ropuamcre::Main()

Main IL Instruction Count

42

Main IL

newobj System.Void Hjgtmizvy.Ghmrj::.ctor() stloc.0 <null> newobj System.Void Hjgtmizvy.Neknrcz::.ctor() stloc.1 <null> newobj System.Void Hjgtmizvy.Xfazcuq::.ctor() stloc.2 <null> newobj System.Void Hjgtmizvy.Hdpaizs::.ctor() stloc.3 <null> ldloc.1 <null> ldloc.2 <null> ldloc.3 <null> newobj System.Void Hjgtmizvy.Wbyyw::.ctor(Hjgtmizvy.Neknrcz,Hjgtmizvy.Xfazcuq,Hjgtmizvy.Hdpaizs) stloc.s V_4 ldloc.0 <null> ldloc.s V_4 ldftn System.Void Hjgtmizvy.Wbyyw::Yaipqqvr(System.Object,Hjgtmizvy.Heecfxmlwu) newobj System.Void System.EventHandler`1<Hjgtmizvy.Heecfxmlwu>::.ctor(System.Object,System.IntPtr) callvirt System.Void Hjgtmizvy.Ghmrj::add_DownloadCompleted(System.EventHandler`1<Hjgtmizvy.Heecfxmlwu>) ldloc.1 <null> ldloc.s V_4 ldftn System.Void Hjgtmizvy.Wbyyw::Tbhjnu(System.Object,Hjgtmizvy.Ggijucy) newobj System.Void System.EventHandler`1<Hjgtmizvy.Ggijucy>::.ctor(System.Object,System.IntPtr) callvirt System.Void Hjgtmizvy.Neknrcz::add_DecryptionCompleted(System.EventHandler`1<Hjgtmizvy.Ggijucy>) ldloc.2 <null> ldloc.s V_4 ldftn System.Void Hjgtmizvy.Wbyyw::Qvnenensm(System.Object,Hjgtmizvy.Aeeie) newobj System.Void System.EventHandler`1<Hjgtmizvy.Aeeie>::.ctor(System.Object,System.IntPtr) callvirt System.Void Hjgtmizvy.Xfazcuq::add_LoadCompleted(System.EventHandler`1<Hjgtmizvy.Aeeie>) ldloc.3 <null> ldloc.s V_4 ldftn System.Void Hjgtmizvy.Wbyyw::Bawgwvgq(System.Object,Hjgtmizvy.Lxkbdgiqezp) newobj System.Void System.EventHandler`1<Hjgtmizvy.Lxkbdgiqezp>::.ctor(System.Object,System.IntPtr) callvirt System.Void Hjgtmizvy.Hdpaizs::add_InvocationCompleted(System.EventHandler`1<Hjgtmizvy.Lxkbdgiqezp>) ldloc.0 <null> callvirt System.Void Hjgtmizvy.Ghmrj::Ihwkrgljdh() leave.s IL_0082: ret ldloc.s V_4 brfalse.s IL_0081: endfinally ldloc.s V_4 callvirt System.Void System.IDisposable::Dispose() endfinally <null> ret <null>

9fc714794e26467a9f9054ffc8de3801 (395.78 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙