Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5: c0b21fe122fa7d6563cce97952cf5eb3
Size: 1.56 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 c0b21fe122fa7d6563cce97952cf5eb3
Sha1 ed5d6006accdb5013bc01a679f41b855333b87da
Sha256 80dd765c830f488c111c61f86d1f1b3822fb75b5d91c4abe23099bc7e2fa3f81
Sha384 84c92b4a6b220c57ed8455321d335c651b1d41f7098deca4cd8c02876bceca9dbd34196a092417a0139f206600a0ed2e
Sha512 6c4d2831b54f5281742aa48487f4b181fd0eb50c5c6d363f7cf26df82ba0a48981ea82e5f2267302d1652330e6d65f59be62305e0124025f2dfe9f3fcb2a9d55
SSDeep 24576:1OOge4KVP+x7MobEMWpvgXhlE4PIiu6Ykt671HM45n2ttOG7lXmw:1OO4/E4PIrvkt6a452twAm
TLSH 7C758D017E94CE51F0181677C1EF42048BB0ED516AA6E72BBCBA3A7D54123A77D0E9CB
Name Value
Module Name
qJeAs6UkRu7G
Full Name
qJeAs6UkRu7G
EntryPoint
System.Void u3k6MrQnihsl6DZKGsN.Upj4PtQcxnPSlFTyUg5::xLqX8fHhbo()
Scope Name
qJeAs6UkRu7G
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
fQAHo3g
Assembly Version
2.9.7.9
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void u3k6MrQnihsl6DZKGsN.Upj4PtQcxnPSlFTyUg5::xLqX8fHhbo()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void HISpgg6VO1q589ElaVf.HrPxRQ62Zxotq2u7Sge::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object u3k6MrQnihsl6DZKGsN.Upj4PtQcxnPSlFTyUg5::Q4CX2VBgh3
callvirt System.Void ARx6TiQ25JyHyu5vBQM.MtuN2GQTxPVH0OU48t3::GTVTIHbv5j()
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙