Malicious
Malicious

b2aab6640273761290e7dc4f51eff09d

PE Executable
|
MD5: b2aab6640273761290e7dc4f51eff09d
|
Size: 847.36 KB
|
application/x-dosexec

Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
b2aab6640273761290e7dc4f51eff09d
Sha1
07b00385fbbad671ae7932619a26142521adc6a8
Sha256
995b5a85b3650f2f1be1f5b8a65c639976fa1749240e97935a9c3b6ea85470eb
Sha384
6d677e2992e7acd2b199f11985cac60f9ba84bdd134b29eeb44b792be7b86dfd6b5f7ce24008bf2a5b5e6b505c9d6b1a
Sha512
d672379ffd2c78b8873518eb7577f4ebdb0fcdfc08ba373a5351a870c6ec5f191683660104a81312776d81f1a28b3ab57920f1dde0271977b6a50a1b429d2170
SSDeep
12288:cnhzmkuwtEo5vYEtrfJiOMHRbQBlUYSw6zVtBnZ8OFWYoCeqAac6TxsEo:cZ8SEo5vYtHRUIYC9Z8oTxDo
TLSH
CD05E6017E44CA11F01D1233C2EF494847B4A8516AE6E36B7DBA376E19123A73E2D9DF

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
kDsOvZUFjPT29C7yiI.S8CMnXIJXUReB1ARqi
v5PvR94bs1fIEAXheG.11GyKBo18qVqm2rBQr
Informations
Name
Value
Module Name

AnkANXlyz8Grcw6twhb8tVwjcMvK

Full Name

AnkANXlyz8Grcw6twhb8tVwjcMvK

EntryPoint

System.Void mlFhmLZydfC63lCkU81.E5NgXSZdgO9lWHJoBxu::VX3Nrc1MFj()

Scope Name

AnkANXlyz8Grcw6twhb8tVwjcMvK

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

2uP6NpgwtGCC

Assembly Version

2.1.8.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

63

Main Method

System.Void mlFhmLZydfC63lCkU81.E5NgXSZdgO9lWHJoBxu::VX3Nrc1MFj()

Main IL Instruction Count

14

Main IL

br.s IL_000B: ldc.i4.0 call <null> ldnull <null> ldc.i4.0 <null> ldelem.ref <null> pop <null> ldc.i4.0 <null> brtrue.s IL_0007: ldnull call System.Void DnpHmsfKG027Wcb8Teu.WwDJEmfmBcaKNGpE5PV::kLjw4iIsCLsZtxc4lksN0j() nop <null> ldsfld System.Object mlFhmLZydfC63lCkU81.E5NgXSZdgO9lWHJoBxu::IrSNEBDOVs callvirt System.Void gI2wH5ZmoVmV5QC5hDh.mmFmqUZRMKgv88S5slo::VyO1DDU8l7() nop <null> ret <null>

Module Name

AnkANXlyz8Grcw6twhb8tVwjcMvK

Full Name

AnkANXlyz8Grcw6twhb8tVwjcMvK

EntryPoint

System.Void mlFhmLZydfC63lCkU81.E5NgXSZdgO9lWHJoBxu::VX3Nrc1MFj()

Scope Name

AnkANXlyz8Grcw6twhb8tVwjcMvK

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

2uP6NpgwtGCC

Assembly Version

2.1.8.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

63

Main Method

System.Void mlFhmLZydfC63lCkU81.E5NgXSZdgO9lWHJoBxu::VX3Nrc1MFj()

Main IL Instruction Count

14

Main IL

br.s IL_000B: ldc.i4.0 call <null> ldnull <null> ldc.i4.0 <null> ldelem.ref <null> pop <null> ldc.i4.0 <null> brtrue.s IL_0007: ldnull call System.Void DnpHmsfKG027Wcb8Teu.WwDJEmfmBcaKNGpE5PV::kLjw4iIsCLsZtxc4lksN0j() nop <null> ldsfld System.Object mlFhmLZydfC63lCkU81.E5NgXSZdgO9lWHJoBxu::IrSNEBDOVs callvirt System.Void gI2wH5ZmoVmV5QC5hDh.mmFmqUZRMKgv88S5slo::VyO1DDU8l7() nop <null> ret <null>

b2aab6640273761290e7dc4f51eff09d (847.36 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
kDsOvZUFjPT29C7yiI.S8CMnXIJXUReB1ARqi
v5PvR94bs1fIEAXheG.11GyKBo18qVqm2rBQr
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙