Suspicious
Suspect

a28bfcebb3a0c7b2b8eccb3e84bf71e5

PE Executable
MD5: a28bfcebb3a0c7b2b8eccb3e84bf71e5
Size: 1.85 MB
application/x-dosexec
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
a28bfcebb3a0c7b2b8eccb3e84bf71e5
Sha1
11feac67c9276692083ae24985a5cc243652bd4e
Sha256
f600ae91e2e2fb789235495503f8ab534de9bbf7aa4ac8a26bdc9f6868352102
Sha384
56f50223a99a77ffbfedf25c63bfd97c304b3b8765d0755b7f1f33547af1abe558845fb4df9cdfcd8569439c64c88312
Sha512
71224fde2abab238d6da1d5ede91be2b7ad8bcbd3cdf5e4f682efd6dc7f16799f3e4da124f3196fdcf85a71e4bb3ccc53a86f624a3a77cc12bc6931fc7d39fb3
SSDeep
49152:eA2SAOaT1x3G43h5nPDeBKcICa5RjO1tWE:CfT1g43hJDeCL5
TLSH
0985AE185AE55F67E1BE473784F3AA843771A890FB4BE70BA14435AA08053D65B033FB

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
{b08a8fce-87ff-4be5-b8dd-ef30a89ff4b8}
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Itafowihz.exe

Full Name

Itafowihz.exe

EntryPoint

System.Void .::()

Scope Name

Itafowihz.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Itafowihz

Assembly Version

1.0.4860.11923

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1232

Main Method

System.Void .::()

Main IL Instruction Count

58

Main IL

br IL_008B: newobj System.Void .::.ctor() br IL_0095: stloc.0 br.s IL_005C: ldloc.0 br.s IL_005F: callvirt System.String .::() brfalse.s IL_005A: leave.s IL_008A br.s IL_0066: ldloc.0 br.s IL_0069: call System.Type[] .::(.) ldsfld System.Func`2<System.Type,System.Boolean> ./:: dup <null> brtrue.s IL_0033: br.s IL_0070 pop <null> ldsfld ./ ./:: ldftn System.Boolean ./::(System.Type) newobj System.Void System.Func`2<System.Type,System.Boolean>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Func`2<System.Type,System.Boolean> ./:: br.s IL_0070: call System.Collections.Generic.IEnumerable`1<System.Type> System.Linq.Enumerable::Where<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>,System.Func`2<System.Type,System.Boolean>) br.s IL_0077: stloc.1 br.s IL_007A: ldloc.1 call System.Int32 System.Linq.Enumerable::Count<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldc.i4.0 <null> ble.s IL_005A: leave.s IL_008A ldloc.1 <null> call System.Type System.Linq.Enumerable::First<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldstr yYWpB4Arr ldc.i4 256 ldnull <null> ldnull <null> ldnull <null> callvirt System.Object System.Type::InvokeMember(System.String,System.Reflection.BindingFlags,System.Reflection.Binder,System.Object,System.Object[]) pop <null> leave.s IL_008A: ret ldloc.0 <null> br.s IL_000C: br.s IL_005F callvirt System.String .::() br.s IL_000E: brfalse.s IL_005A ldloc.0 <null> br.s IL_0012: br.s IL_0069 call System.Type[] .::(.) br.s IL_0014: ldsfld System.Func`2<System.Type,System.Boolean> ./:: call System.Collections.Generic.IEnumerable`1<System.Type> System.Linq.Enumerable::Where<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>,System.Func`2<System.Type,System.Boolean>) br.s IL_0035: br.s IL_0077 stloc.1 <null> br.s IL_0037: br.s IL_007A ldloc.1 <null> br.s IL_0039: call System.Int32 System.Linq.Enumerable::Count<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldloc.0 <null> brfalse.s IL_0086: ldc.i4.3 ldloc.0 <null> callvirt System.Void System.IDisposable::Dispose() ldc.i4.3 <null> brfalse.s IL_007D: ldloc.0 endfinally <null> ret <null> newobj System.Void .::.ctor() br IL_0005: br IL_0095 stloc.0 <null> br IL_000A: br.s IL_005C

Module Name

Itafowihz.exe

Full Name

Itafowihz.exe

EntryPoint

System.Void .::()

Scope Name

Itafowihz.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Itafowihz

Assembly Version

1.0.4860.11923

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1232

Main Method

System.Void .::()

Main IL Instruction Count

58

Main IL

br IL_008B: newobj System.Void .::.ctor() br IL_0095: stloc.0 br.s IL_005C: ldloc.0 br.s IL_005F: callvirt System.String .::() brfalse.s IL_005A: leave.s IL_008A br.s IL_0066: ldloc.0 br.s IL_0069: call System.Type[] .::(.) ldsfld System.Func`2<System.Type,System.Boolean> ./:: dup <null> brtrue.s IL_0033: br.s IL_0070 pop <null> ldsfld ./ ./:: ldftn System.Boolean ./::(System.Type) newobj System.Void System.Func`2<System.Type,System.Boolean>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Func`2<System.Type,System.Boolean> ./:: br.s IL_0070: call System.Collections.Generic.IEnumerable`1<System.Type> System.Linq.Enumerable::Where<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>,System.Func`2<System.Type,System.Boolean>) br.s IL_0077: stloc.1 br.s IL_007A: ldloc.1 call System.Int32 System.Linq.Enumerable::Count<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldc.i4.0 <null> ble.s IL_005A: leave.s IL_008A ldloc.1 <null> call System.Type System.Linq.Enumerable::First<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldstr yYWpB4Arr ldc.i4 256 ldnull <null> ldnull <null> ldnull <null> callvirt System.Object System.Type::InvokeMember(System.String,System.Reflection.BindingFlags,System.Reflection.Binder,System.Object,System.Object[]) pop <null> leave.s IL_008A: ret ldloc.0 <null> br.s IL_000C: br.s IL_005F callvirt System.String .::() br.s IL_000E: brfalse.s IL_005A ldloc.0 <null> br.s IL_0012: br.s IL_0069 call System.Type[] .::(.) br.s IL_0014: ldsfld System.Func`2<System.Type,System.Boolean> ./:: call System.Collections.Generic.IEnumerable`1<System.Type> System.Linq.Enumerable::Where<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>,System.Func`2<System.Type,System.Boolean>) br.s IL_0035: br.s IL_0077 stloc.1 <null> br.s IL_0037: br.s IL_007A ldloc.1 <null> br.s IL_0039: call System.Int32 System.Linq.Enumerable::Count<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldloc.0 <null> brfalse.s IL_0086: ldc.i4.3 ldloc.0 <null> callvirt System.Void System.IDisposable::Dispose() ldc.i4.3 <null> brfalse.s IL_007D: ldloc.0 endfinally <null> ret <null> newobj System.Void .::.ctor() br IL_0005: br IL_0095 stloc.0 <null> br IL_000A: br.s IL_005C

a28bfcebb3a0c7b2b8eccb3e84bf71e5 (1.85 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙