Suspicious
Suspect

PE Executable
MD5: a55aadde092c1865f890959271b8f9d5
Size: 1.47 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 a55aadde092c1865f890959271b8f9d5
Sha1 f2042883f706a530d066dd543182b7b87cdff53c
Sha256 00d76b06a5f9a7d23c7fc78c9f83b08d84e4a8a84e8da0a852ec0f6c5e65e771
Sha384 28487baeddac5b7f99247508bda4357b59de2aa5a9964f67853279ac55f5bbb61daf48d823a9c339b5b28ac687f32360
Sha512 98e3436ad4d354c98cba3f85098b08dd4772bdcc4577d53a603108a1eb92875974c918c14142d2461c16ab73ee7dce115ae58ae71957ebf47003e8f85f58f1dc
SSDeep 24576:Flv/tnIpTdOlzAVRa9YVQ+G0BRijs3RovcaoQrgDdFlDhBT:Fl3tIr66pVBRi+BXDdFlDPT
TLSH B665CF45E2C9EC8AE01B2271983CF534255EF759A27BCD5A2A19B87961B33837017F0F
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Egplimxr.Properties.Resources.resources
Hpkjml
Name Value
Module Name
Thjmbne.exe
Full Name
Thjmbne.exe
EntryPoint
System.Void Egplimxr.Oyvjjwh::Main()
Scope Name
Thjmbne.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Thjmbne
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
527
Main Method
System.Void Egplimxr.Oyvjjwh::Main()
Main IL Instruction Count
12
Main IL
ldsfld System.Action Egplimxr.Oyvjjwh/<>c::<>9__0_0
dup <null>
brtrue IL_0022: call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action)
pop <null>
ldsfld Egplimxr.Oyvjjwh/<>c Egplimxr.Oyvjjwh/<>c::<>9
ldftn System.Void Egplimxr.Oyvjjwh/<>c::<Main>b__0_0()
newobj System.Void System.Action::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.Action Egplimxr.Oyvjjwh/<>c::<>9__0_0
call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action)
callvirt System.Void System.Threading.Tasks.Task::Wait()
ret <null>
Module Name
Thjmbne.exe
Full Name
Thjmbne.exe
EntryPoint
System.Void Egplimxr.Oyvjjwh::Main()
Scope Name
Thjmbne.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Thjmbne
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
527
Main Method
System.Void Egplimxr.Oyvjjwh::Main()
Main IL Instruction Count
12
Main IL
ldsfld System.Action Egplimxr.Oyvjjwh/<>c::<>9__0_0
dup <null>
brtrue IL_0022: call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action)
pop <null>
ldsfld Egplimxr.Oyvjjwh/<>c Egplimxr.Oyvjjwh/<>c::<>9
ldftn System.Void Egplimxr.Oyvjjwh/<>c::<Main>b__0_0()
newobj System.Void System.Action::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.Action Egplimxr.Oyvjjwh/<>c::<>9__0_0
call System.Threading.Tasks.Task System.Threading.Tasks.Task::Run(System.Action)
callvirt System.Void System.Threading.Tasks.Task::Wait()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Egplimxr.Properties.Resources.resources
Hpkjml
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙