Suspicious
Suspect

c157b825a19e77893b8ebe6d43e1165d

PE Executable
|
MD5: c157b825a19e77893b8ebe6d43e1165d
|
Size: 1.02 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
c157b825a19e77893b8ebe6d43e1165d
Sha1
b48b58269e743b7d9ce1b66ee6c55ee18da7beb8
Sha256
738480ab58300675f57080ee683e73d854f5f3ed01cd846c2b0e98116a0d301f
Sha384
506fdeae72e6d53a94d06ffc9cc3bd6bbc3ee4e24bd3284f1429f9e3bfb1d681678fe22c9d2ea806c2c06ef5aff17d81
Sha512
17c0a797fc32f7771e3bfc694dbc83f0c8a0c52087666871fe2228de46cd02db9d1152714218ca08c25693040439c492465865403e67d7b3af9f0d93af058f29
SSDeep
24576:snOl0VmLLdufPNxPb+cUxifkn69DF2CyM:gLmEdxPhX8sJ
TLSH
C325BE011BE94F98F1BF8734A935051447F6FC03CE36DB9E299868ED2972B91AA51333

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Pobregas.67594
ax3BjQ.Resources.resources
e42b56b2d98c4d.Resources.resources
51cf908b0
[NBF]root.Data
51cf908b1
[NBF]root.Data
51cf908b10
[NBF]root.Data
51cf908b11
[NBF]root.Data
51cf908b12
[NBF]root.Data
51cf908b13
[NBF]root.Data
51cf908b14
[NBF]root.Data
51cf908b15
[NBF]root.Data
51cf908b16
[NBF]root.Data
51cf908b17
[NBF]root.Data
51cf908b18
[NBF]root.Data
51cf908b19
[NBF]root.Data
51cf908b2
[NBF]root.Data
51cf908b20
[NBF]root.Data
51cf908b21
[NBF]root.Data
51cf908b22
[NBF]root.Data
51cf908b23
[NBF]root.Data
51cf908b24
[NBF]root.Data
51cf908b25
[NBF]root.Data
51cf908b3
[NBF]root.Data
51cf908b4
[NBF]root.Data
51cf908b5
[NBF]root.Data
51cf908b6
[NBF]root.Data
51cf908b7
[NBF]root.Data
51cf908b8
[NBF]root.Data
51cf908b9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

ax3BjQ

Full Name

ax3BjQ

EntryPoint

System.Void ax3BjQ.cp4JZ1fbac5B::zp4PDxt()

Scope Name

ax3BjQ

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

ax3BjQ

Assembly Version

22.11.22.13

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1427

Main Method

System.Void ax3BjQ.cp4JZ1fbac5B::zp4PDxt()

Main IL Instruction Count

24

Main IL

nop <null> ldstr BackgroundService stloc.0 <null> ldc.i4 70193 stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.s 50 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> nop <null> ldstr 67594 call System.Void ax3BjQ.2jiAroK/ga0SfTb1mt.ry1T7yWas::5gwGjK2mJ(System.String) nop <null> leave.s IL_003D: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_003D: nop nop <null> ret <null>

Module Name

ax3BjQ

Full Name

ax3BjQ

EntryPoint

System.Void ax3BjQ.cp4JZ1fbac5B::zp4PDxt()

Scope Name

ax3BjQ

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

ax3BjQ

Assembly Version

22.11.22.13

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1427

Main Method

System.Void ax3BjQ.cp4JZ1fbac5B::zp4PDxt()

Main IL Instruction Count

24

Main IL

nop <null> ldstr BackgroundService stloc.0 <null> ldc.i4 70193 stloc.1 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> ldc.i4.s 50 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> nop <null> ldstr 67594 call System.Void ax3BjQ.2jiAroK/ga0SfTb1mt.ry1T7yWas::5gwGjK2mJ(System.String) nop <null> leave.s IL_003D: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_003D: nop nop <null> ret <null>

c157b825a19e77893b8ebe6d43e1165d (1.02 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Pobregas.67594
ax3BjQ.Resources.resources
e42b56b2d98c4d.Resources.resources
51cf908b0
[NBF]root.Data
51cf908b1
[NBF]root.Data
51cf908b10
[NBF]root.Data
51cf908b11
[NBF]root.Data
51cf908b12
[NBF]root.Data
51cf908b13
[NBF]root.Data
51cf908b14
[NBF]root.Data
51cf908b15
[NBF]root.Data
51cf908b16
[NBF]root.Data
51cf908b17
[NBF]root.Data
51cf908b18
[NBF]root.Data
51cf908b19
[NBF]root.Data
51cf908b2
[NBF]root.Data
51cf908b20
[NBF]root.Data
51cf908b21
[NBF]root.Data
51cf908b22
[NBF]root.Data
51cf908b23
[NBF]root.Data
51cf908b24
[NBF]root.Data
51cf908b25
[NBF]root.Data
51cf908b3
[NBF]root.Data
51cf908b4
[NBF]root.Data
51cf908b5
[NBF]root.Data
51cf908b6
[NBF]root.Data
51cf908b7
[NBF]root.Data
51cf908b8
[NBF]root.Data
51cf908b9
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙