Suspicious
Suspect

b01d08ccf140cfe2d95a2920637e397f

PE Executable
|
MD5: b01d08ccf140cfe2d95a2920637e397f
|
Size: 1.16 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
b01d08ccf140cfe2d95a2920637e397f
Sha1
672b03b6705eed39ac4110a11166105683f468ce
Sha256
e05eeb1ac0c6722a64e69f2fad8dba483cfdfe97a60f2bd123c4fb33715c419f
Sha384
ba508b6e0193c6ca50ce540cf4f38adf12cb1ec226535dfc4871a1b63356853edcb7e6d1a1415876767a9dd52a59e662
Sha512
072bea936ec9b83fe8941cb1939aa323c32820266c45d4be5370b02fa63b97f081ad1f7fde3ff9d5be222415bb292c7eb490908b71a69d9c358bc8191e45ee9c
SSDeep
12288:tV1ljfZ4ZpG50omh69bwPb6HplP5fvHJQR8Pv6PxH8c/fg2Q6VSBD8p8XNPXyuFQ:TQh2bwAFvHCRYvy9A2Q6ktCuF
TLSH
6935DF1926E69154E0BBD7349BB94A1447F0BA17CA32D32FA14715FDCF6238A25233B3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
xCw6Ez1q2.g.resources
xCw6Ez1q2.Resources.resources
91675fbc6aa166.Resources.resources
fc9e52cd0
[NBF]root.Data
fc9e52cd1
[NBF]root.Data
fc9e52cd10
[NBF]root.Data
fc9e52cd11
[NBF]root.Data
fc9e52cd12
[NBF]root.Data
fc9e52cd13
[NBF]root.Data
fc9e52cd14
[NBF]root.Data
fc9e52cd15
[NBF]root.Data
fc9e52cd16
[NBF]root.Data
fc9e52cd17
[NBF]root.Data
fc9e52cd18
[NBF]root.Data
fc9e52cd19
[NBF]root.Data
fc9e52cd2
[NBF]root.Data
fc9e52cd20
[NBF]root.Data
fc9e52cd21
[NBF]root.Data
fc9e52cd22
[NBF]root.Data
fc9e52cd23
[NBF]root.Data
fc9e52cd24
[NBF]root.Data
fc9e52cd25
[NBF]root.Data
fc9e52cd26
[NBF]root.Data
fc9e52cd27
[NBF]root.Data
fc9e52cd28
[NBF]root.Data
fc9e52cd29
[NBF]root.Data
fc9e52cd3
[NBF]root.Data
fc9e52cd30
[NBF]root.Data
fc9e52cd31
[NBF]root.Data
fc9e52cd32
[NBF]root.Data
fc9e52cd33
[NBF]root.Data
fc9e52cd34
[NBF]root.Data
fc9e52cd35
[NBF]root.Data
fc9e52cd36
[NBF]root.Data
fc9e52cd37
[NBF]root.Data
fc9e52cd4
[NBF]root.Data
fc9e52cd5
[NBF]root.Data
fc9e52cd6
[NBF]root.Data
fc9e52cd7
[NBF]root.Data
fc9e52cd8
[NBF]root.Data
fc9e52cd9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

xCw6Ez1q2

Full Name

xCw6Ez1q2

EntryPoint

System.Void xCw6Ez1q2.xn0FqQw::Bc6jnDa15wgYr()

Scope Name

xCw6Ez1q2

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

xCw6Ez1q2

Assembly Version

7.18.26.274

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1005

Main Method

System.Void xCw6Ez1q2.xn0FqQw::Bc6jnDa15wgYr()

Main IL Instruction Count

106

Main IL

nop <null> nop <null> newobj System.Void xCw6Ez1q2.xn0FqQw::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.3 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_4 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_5 ldloc.s V_4 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0051: ldloc.3 br.s IL_006E: ldloc.s V_5 ldloc.3 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken xCw6Ez1q2.xn0FqQw call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass xCw6Ez1q2.xn0FqQw stloc.0 <null> ldloc.s V_5 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> leave.s IL_00ED: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_6 nop <null> nop <null> ldc.i4 214 stloc.s V_7 br.s IL_00B1: ldloc.s V_7 ldloc.s V_7 ldc.i4.3 <null> mul.ovf <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 24 cgt <null> stloc.s V_9 ldloc.s V_9 brfalse.s IL_00AF: nop ldc.i4.s 24 stloc.s V_7 ldstr resources/9875193 call System.Byte[] xCw6Ez1q2.mm9A8Qt::1ZxzR(System.String) stloc.s V_8 br.s IL_00BF: ldloc.s V_8 nop <null> nop <null> ldloc.s V_7 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_10 ldloc.s V_10 brtrue.s IL_008B: ldloc.s V_7 ldloc.s V_8 castclass System.Byte[] call System.Void xCw6Ez1q2.Rg4qt/bj7GS5yg.7BkkY::Fgq59PjjniN(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_11 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00ED: nop nop <null> ret <null>

Module Name

xCw6Ez1q2

Full Name

xCw6Ez1q2

EntryPoint

System.Void xCw6Ez1q2.xn0FqQw::Bc6jnDa15wgYr()

Scope Name

xCw6Ez1q2

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

xCw6Ez1q2

Assembly Version

7.18.26.274

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1005

Main Method

System.Void xCw6Ez1q2.xn0FqQw::Bc6jnDa15wgYr()

Main IL Instruction Count

106

Main IL

nop <null> nop <null> newobj System.Void xCw6Ez1q2.xn0FqQw::.ctor() stloc.0 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Object::.ctor() ldnull <null> ldstr CreateTab ldc.i4.2 <null> newarr System.Object dup <null> ldc.i4.0 <null> ldstr segmen stelem.ref <null> dup <null> ldc.i4.1 <null> ldloc.0 <null> stelem.ref <null> dup <null> stloc.3 <null> ldnull <null> ldnull <null> ldc.i4.2 <null> newarr System.Boolean dup <null> ldc.i4.1 <null> ldc.i4.1 <null> stelem.i1 <null> dup <null> stloc.s V_4 call System.Object Microsoft.VisualBasic.CompilerServices.NewLateBinding::LateGet(System.Object,System.Type,System.String,System.Object[],System.String[],System.Type[],System.Boolean[]) stloc.s V_5 ldloc.s V_4 ldc.i4.1 <null> ldelem.u1 <null> brtrue.s IL_0051: ldloc.3 br.s IL_006E: ldloc.s V_5 ldloc.3 <null> ldc.i4.1 <null> ldelem.ref <null> call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) ldtoken xCw6Ez1q2.xn0FqQw call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle) call System.Object Microsoft.VisualBasic.CompilerServices.Conversions::ChangeType(System.Object,System.Type) castclass xCw6Ez1q2.xn0FqQw stloc.0 <null> ldloc.s V_5 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.2 <null> leave.s IL_00ED: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_6 nop <null> nop <null> ldc.i4 214 stloc.s V_7 br.s IL_00B1: ldloc.s V_7 ldloc.s V_7 ldc.i4.3 <null> mul.ovf <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 24 cgt <null> stloc.s V_9 ldloc.s V_9 brfalse.s IL_00AF: nop ldc.i4.s 24 stloc.s V_7 ldstr resources/9875193 call System.Byte[] xCw6Ez1q2.mm9A8Qt::1ZxzR(System.String) stloc.s V_8 br.s IL_00BF: ldloc.s V_8 nop <null> nop <null> ldloc.s V_7 ldc.i4.s 24 rem <null> ldc.i4.0 <null> cgt.un <null> stloc.s V_10 ldloc.s V_10 brtrue.s IL_008B: ldloc.s V_7 ldloc.s V_8 castclass System.Byte[] call System.Void xCw6Ez1q2.Rg4qt/bj7GS5yg.7BkkY::Fgq59PjjniN(System.Byte[]) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> leave.s IL_00E5: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_11 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00E5: nop nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_00ED: nop nop <null> ret <null>

b01d08ccf140cfe2d95a2920637e397f (1.16 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
xCw6Ez1q2.g.resources
xCw6Ez1q2.Resources.resources
91675fbc6aa166.Resources.resources
fc9e52cd0
[NBF]root.Data
fc9e52cd1
[NBF]root.Data
fc9e52cd10
[NBF]root.Data
fc9e52cd11
[NBF]root.Data
fc9e52cd12
[NBF]root.Data
fc9e52cd13
[NBF]root.Data
fc9e52cd14
[NBF]root.Data
fc9e52cd15
[NBF]root.Data
fc9e52cd16
[NBF]root.Data
fc9e52cd17
[NBF]root.Data
fc9e52cd18
[NBF]root.Data
fc9e52cd19
[NBF]root.Data
fc9e52cd2
[NBF]root.Data
fc9e52cd20
[NBF]root.Data
fc9e52cd21
[NBF]root.Data
fc9e52cd22
[NBF]root.Data
fc9e52cd23
[NBF]root.Data
fc9e52cd24
[NBF]root.Data
fc9e52cd25
[NBF]root.Data
fc9e52cd26
[NBF]root.Data
fc9e52cd27
[NBF]root.Data
fc9e52cd28
[NBF]root.Data
fc9e52cd29
[NBF]root.Data
fc9e52cd3
[NBF]root.Data
fc9e52cd30
[NBF]root.Data
fc9e52cd31
[NBF]root.Data
fc9e52cd32
[NBF]root.Data
fc9e52cd33
[NBF]root.Data
fc9e52cd34
[NBF]root.Data
fc9e52cd35
[NBF]root.Data
fc9e52cd36
[NBF]root.Data
fc9e52cd37
[NBF]root.Data
fc9e52cd4
[NBF]root.Data
fc9e52cd5
[NBF]root.Data
fc9e52cd6
[NBF]root.Data
fc9e52cd7
[NBF]root.Data
fc9e52cd8
[NBF]root.Data
fc9e52cd9
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙