Suspicious
Suspect

Share on LinkedIn
Print
PE Executable
MD5: c0e8b952d48131029fc522b33856dd38
Size: 1.05 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 c0e8b952d48131029fc522b33856dd38
Sha1 2379540ef40bd5bdd30375786715eb0ca8e10256
Sha256 49c288bdd977b430764c2067d4e25cb45dbbfb55105a080458af03221e776f63
Sha384 3091a46ecdcbaf5dfaeddfdc087596dfd35ffb1f7b197bafdb40540e448c08d997a75590f600aaaaea672301264b5351
Sha512 b2a2a64b9dd75308281313d5cc62b250e82950f9ee9856f0aeb5c600f2edd191d8eb819a929afb81fdc2a1d1918665e5404f0cfb094408c387e5b4d9d3199bda
SSDeep 24576:BrffG8hq8v2T/XBi69AZmZjaNCvJaRO6AymAVHe/:BtVvOnAYiAaRAymgHe
TLSH 34251160765ADD13D4798AF96032E3B543B26E5DE426C3CA9DC9FCE778F6B002850683
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Dorixona.Bimor.resources
Dorixona.Dorixona.resources
Dorixona.Firma.resources
Dorixona.Form1.resources
$this.Icon
[NBF]root.IconData
Dorixona.Properties.Resources.resources
DZoF
[NBF]root.Data
[NBF]root.Data-preview.png
nd
[NBF]root.Data
Name Value
Module Name
XtcS.exe
Full Name
XtcS.exe
EntryPoint
System.Void Dorixona.Program::Main()
Scope Name
XtcS.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XtcS
Assembly Version
4.0.0.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
473
Main Method
System.Void Dorixona.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Dorixona.Login::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
XtcS.exe
Full Name
XtcS.exe
EntryPoint
System.Void Dorixona.Program::Main()
Scope Name
XtcS.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XtcS
Assembly Version
4.0.0.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
473
Main Method
System.Void Dorixona.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void Dorixona.Login::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
PDB Path PATH
Xthuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙