Suspicious
Suspect

bc844f17ed398e822211871d436df134

PE Executable
MD5: bc844f17ed398e822211871d436df134
Size: 646.14 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 bc844f17ed398e822211871d436df134
Sha1 84ccb3a7eeb6ff805ab372f0466cfab49dda09e8
Sha256 b405513249de55aa8da7e970475fd42c0057f6cc1a8b91c04ff38b59a18ae9ca
Sha384 ed3158bcdcb6a01f3efe911090b36b56ebdd3379c4f819cdc38e759d0f293da5a568cacc7894e89de1df2c0e6217df09
Sha512 c585114a5f4dfb11d6efa43c7daf762ca8d877248c6f11bb20c9d96c02bd1243aa109015d7fd535fceb0fedafcb2be759727e6a8040a81ca2d4af9df42084409
SSDeep 6144:RdhEcKDgKiJwqohLam3GLjnje6VlWT8b9DxHKcHbCcQGlpirC2/z9FDEbb3uHiEC:bJK8KzaK4jPVle8JxtbTQgc9FD8e1Hi
TLSH 35D46E0CBE91E805DE1E3DB7CFEA11004B716DC1AE1195463109BFEE8B763B259A627C
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
esqqcvifwiuz
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
velocity.exe
Full Name
velocity.exe
EntryPoint
System.Void dAKpmGhBlNr.wfmEmOcUkppt::xlFJrYtnDabQion(System.String[])
Scope Name
velocity.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
velocity
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1546
Main Method
System.Void dAKpmGhBlNr.wfmEmOcUkppt::xlFJrYtnDabQion(System.String[])
Main IL Instruction Count
57
Main IL
ldc.r8 3373
stloc.0 <null>
br IL_00EC: br IL_000F
nop <null>
ldloc.0 <null>
ldc.r8 3386
ceq <null>
brfalse IL_0030: nop
call System.Void dAKpmGhBlNr.wfmEmOcUkppt::FUNAYeFSyJKzTFo()
ldc.r8 3388
stloc.0 <null>
nop <null>
ldloc.0 <null>
ldc.r8 3388
ceq <null>
brfalse IL_0097: nop
newobj System.Void System.Random::.ctor()
nop <null>
ldc.r8 3992.399097540458
ldc.r8 2000
call System.Double System.Math::Log(System.Double)
add <null>
call System.Int32 System.Convert::ToInt32(System.Double)
nop <null>
ldc.r8 9000
ldc.r8 3000
call System.Double System.Math::Truncate(System.Double)
sub <null>
call System.Int32 System.Convert::ToInt32(System.Double)
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldc.r8 3389
stloc.0 <null>
nop <null>
ldloc.0 <null>
ldc.r8 3389
ceq <null>
brfalse IL_00B8: nop
call System.Void GqKALHsPNZPIqg.kPQlQKUrLs::NHffHBvAHo()
ldc.r8 3398
stloc.0 <null>
nop <null>
ldloc.0 <null>
ldc.r8 3373
ceq <null>
brfalse IL_00D5: nop
nop <null>
ldc.r8 3386
stloc.0 <null>
nop <null>
ldloc.0 <null>
ldc.r8 3398
ceq <null>
brfalse IL_00EC: br IL_000F
br IL_00F1: ret
br IL_000F: nop
ret <null>
Module Name
velocity.exe
Full Name
velocity.exe
EntryPoint
System.Void dAKpmGhBlNr.wfmEmOcUkppt::xlFJrYtnDabQion(System.String[])
Scope Name
velocity.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
velocity
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
1546
Main Method
System.Void dAKpmGhBlNr.wfmEmOcUkppt::xlFJrYtnDabQion(System.String[])
Main IL Instruction Count
57
Main IL
ldc.r8 3373
stloc.0 <null>
br IL_00EC: br IL_000F
nop <null>
ldloc.0 <null>
ldc.r8 3386
ceq <null>
brfalse IL_0030: nop
call System.Void dAKpmGhBlNr.wfmEmOcUkppt::FUNAYeFSyJKzTFo()
ldc.r8 3388
stloc.0 <null>
nop <null>
ldloc.0 <null>
ldc.r8 3388
ceq <null>
brfalse IL_0097: nop
newobj System.Void System.Random::.ctor()
nop <null>
ldc.r8 3992.399097540458
ldc.r8 2000
call System.Double System.Math::Log(System.Double)
add <null>
call System.Int32 System.Convert::ToInt32(System.Double)
nop <null>
ldc.r8 9000
ldc.r8 3000
call System.Double System.Math::Truncate(System.Double)
sub <null>
call System.Int32 System.Convert::ToInt32(System.Double)
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldc.r8 3389
stloc.0 <null>
nop <null>
ldloc.0 <null>
ldc.r8 3389
ceq <null>
brfalse IL_00B8: nop
call System.Void GqKALHsPNZPIqg.kPQlQKUrLs::NHffHBvAHo()
ldc.r8 3398
stloc.0 <null>
nop <null>
ldloc.0 <null>
ldc.r8 3373
ceq <null>
brfalse IL_00D5: nop
nop <null>
ldc.r8 3386
stloc.0 <null>
nop <null>
ldloc.0 <null>
ldc.r8 3398
ceq <null>
brfalse IL_00EC: br IL_000F
br IL_00F1: ret
br IL_000F: nop
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
esqqcvifwiuz
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙