Suspicious
Suspect

a3850bfb4b8e3ad0c19466e635a94cd8

PE Executable
|
MD5: a3850bfb4b8e3ad0c19466e635a94cd8
|
Size: 610.82 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
a3850bfb4b8e3ad0c19466e635a94cd8
Sha1
e4b944b50d8f661a5e12bebb74670de6c21641fe
Sha256
2ce473b1702af7cd8c8a391fcaf6e4d6b8687100ee6518e52a02adfc86735dee
Sha384
de84b8b96b29709bd22d0fdc20c125a05e97163d65401c7276834438d1fed637b064d2d6db103b8ee423688e2c8253fc
Sha512
24a9ab4895e027ccc2039f90af56a7dc4107f9d0c5766f487796b1a7851538e9e70177306870e8128a682d55313533b6ea8ed753374aa1f5f8a3e7d0eb98c1f7
SSDeep
12288:FV1l3zZjrx550omh69bOYzcqn0DmT0xrbaSv:dQh2bOwcOkbaS
TLSH
41D4AD5833EA9244F17F97349E7A4A004BF0B903CA32C61FE69758ED8B6678455237B3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
7WntipD96p.g.resources
7WntipD96p.Resources.resources
15dc294803eccf.Resources.resources
0fcc32900
[NBF]root.Data
0fcc32901
[NBF]root.Data
0fcc32902
[NBF]root.Data
0fcc32903
[NBF]root.Data
0fcc32904
[NBF]root.Data
0fcc32905
[NBF]root.Data
0fcc32906
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

7WntipD96p

Full Name

7WntipD96p

EntryPoint

System.Void 7WntipD96p.Hnz91mYmMyi6::so0F8m()

Scope Name

7WntipD96p

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

7WntipD96p

Assembly Version

11.14.3.45

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1005

Main Method

System.Void 7WntipD96p.Hnz91mYmMyi6::so0F8m()

Main IL Instruction Count

106

Main IL

nop <null> nop <null> newobj System.Void 7WntipD96p.Hnz91mYmMyi6::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.3 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_4 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_5 ldloc.s V_4 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0051: ldloc.3 br.s IL_006E: ldloc.s V_5 ldloc.3 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken 7WntipD96p.Hnz91mYmMyi6 call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass 7WntipD96p.Hnz91mYmMyi6 stloc.0 <null> ldloc.s V_5 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> leave.s IL_00ED: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_6 nop <null> nop <null> ldc.i4 214 stloc.s V_7 br.s IL_00B1: ldloc.s V_7 ldloc.s V_7 ldc.i4.3 <null> mul.ovf <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 24 cgt <null> stloc.s V_9 ldloc.s V_9 brfalse.s IL_00AF: nop ldc.i4.s 24 stloc.s V_7 ldstr resources/9875193 call System.Byte[] 7WntipD96p.9peJa::9MosRyd20pLa(System.String) stloc.s V_8 br.s IL_00BF: ldloc.s V_8 nop <null> nop <null> ldloc.s V_7 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_10 ldloc.s V_10 brtrue.s IL_008B: ldloc.s V_7 ldloc.s V_8 castclass System.Byte[] call System.Void 7WntipD96p.rf0H2Cgck3/Wi1er4iPS.dt6Sw2JaYm5yx::Sxa38Tzid_1K(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_11 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00ED: nop nop <null> ret <null>

Module Name

7WntipD96p

Full Name

7WntipD96p

EntryPoint

System.Void 7WntipD96p.Hnz91mYmMyi6::so0F8m()

Scope Name

7WntipD96p

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

7WntipD96p

Assembly Version

11.14.3.45

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1005

Main Method

System.Void 7WntipD96p.Hnz91mYmMyi6::so0F8m()

Main IL Instruction Count

106

Main IL

nop <null> nop <null> newobj System.Void 7WntipD96p.Hnz91mYmMyi6::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.3 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_4 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_5 ldloc.s V_4 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0051: ldloc.3 br.s IL_006E: ldloc.s V_5 ldloc.3 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken 7WntipD96p.Hnz91mYmMyi6 call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass 7WntipD96p.Hnz91mYmMyi6 stloc.0 <null> ldloc.s V_5 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> leave.s IL_00ED: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_6 nop <null> nop <null> ldc.i4 214 stloc.s V_7 br.s IL_00B1: ldloc.s V_7 ldloc.s V_7 ldc.i4.3 <null> mul.ovf <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 24 cgt <null> stloc.s V_9 ldloc.s V_9 brfalse.s IL_00AF: nop ldc.i4.s 24 stloc.s V_7 ldstr resources/9875193 call System.Byte[] 7WntipD96p.9peJa::9MosRyd20pLa(System.String) stloc.s V_8 br.s IL_00BF: ldloc.s V_8 nop <null> nop <null> ldloc.s V_7 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_10 ldloc.s V_10 brtrue.s IL_008B: ldloc.s V_7 ldloc.s V_8 castclass System.Byte[] call System.Void 7WntipD96p.rf0H2Cgck3/Wi1er4iPS.dt6Sw2JaYm5yx::Sxa38Tzid_1K(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_11 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00ED: nop nop <null> ret <null>

a3850bfb4b8e3ad0c19466e635a94cd8 (610.82 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
7WntipD96p.g.resources
7WntipD96p.Resources.resources
15dc294803eccf.Resources.resources
0fcc32900
[NBF]root.Data
0fcc32901
[NBF]root.Data
0fcc32902
[NBF]root.Data
0fcc32903
[NBF]root.Data
0fcc32904
[NBF]root.Data
0fcc32905
[NBF]root.Data
0fcc32906
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙