Malicious
Malicious

c34be59dd65449f1f59567c0649d6903

PE Executable
|
MD5: c34be59dd65449f1f59567c0649d6903
|
Size: 3.52 MB
|
application/x-dosexec


Print
Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Low

Hash
Hash Value
MD5
c34be59dd65449f1f59567c0649d6903
Sha1
a3657a58e0d85d21d8acee059b837c6ba2860a08
Sha256
e9dce2033fb62b6f35f744c078669ac8862bba1f88343797f3dce905dd8f3c83
Sha384
7e9d6ff5a280d81b77e076471145296d44cc661c2dee161c66353e759c423045f519ffa0f205905649d6e06b67691753
Sha512
818b091dc8b14a0c09182186ae88a8d8e04bd2ad7f3cc1f1a591542c02ef3a7b0e430d625aa750ed0ca35d0ccf9b9806558c47696dde072d79d37de219373cda
SSDeep
49152:9sKMKueAwS4OwjZ4KtXtcdpXtdG6P7EQEMhCjmPCiJDq:9sKMKhSXdXEMdPCiJ
TLSH
FCF55B1BFA8E5AA2D241B77BC6F704272367D5612327D31B7A9EA33988077774E81103

PeID

.NET executable
HQR data file
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual C++ v6.0 DLL
Microsoft Visual Studio .NET
UPolyX 0.3 -> delikon
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Vbbusnq.Properties.Resources.resources
Ouqrizme
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Jlwoq.exe

Full Name

Jlwoq.exe

EntryPoint

System.Void SteamKit2.Matching.MatcherExecutor::MatchSortedMatcher()

Scope Name

Jlwoq.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Jlwoq

Assembly Version

1.0.4628.12714

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1291

Main Method

System.Void SteamKit2.Matching.MatcherExecutor::MatchSortedMatcher()

Main IL Instruction Count

18

Main IL

ldc.i4 1 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0024: ret ret <null> newobj System.Void SteamKit2.Testing.MatcherTester::.ctor() call System.Byte[] SteamKit2.Testing.MatcherTester::InspectEditableTester() call System.Byte[] SteamKit2.Concurrency.WorkerRequester::RunDetailedWorker(System.Object) call System.Void SteamKit2.Collections.SolverDic::RetrieveFlexibleDic(System.Object) ldc.i4 0 ldsfld <Module>{6d9d8a6d-70ec-4c85-ac66-327556108fee} <Module>{6d9d8a6d-70ec-4c85-ac66-327556108fee}::m_f9533508d37249a1856916e014ee130b ldfld System.Int32 <Module>{6d9d8a6d-70ec-4c85-ac66-327556108fee}::m_6f300155b5724d22a7694aeed8aee7ab brtrue IL_0012: switch(IL_0024,IL_0025) pop <null> ldc.i4 0 br IL_0012: switch(IL_0024,IL_0025)

Module Name

Jlwoq.exe

Full Name

Jlwoq.exe

EntryPoint

System.Void SteamKit2.Matching.MatcherExecutor::MatchSortedMatcher()

Scope Name

Jlwoq.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Jlwoq

Assembly Version

1.0.4628.12714

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1291

Main Method

System.Void SteamKit2.Matching.MatcherExecutor::MatchSortedMatcher()

Main IL Instruction Count

18

Main IL

ldc.i4 1 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_0024: ret ret <null> newobj System.Void SteamKit2.Testing.MatcherTester::.ctor() call System.Byte[] SteamKit2.Testing.MatcherTester::InspectEditableTester() call System.Byte[] SteamKit2.Concurrency.WorkerRequester::RunDetailedWorker(System.Object) call System.Void SteamKit2.Collections.SolverDic::RetrieveFlexibleDic(System.Object) ldc.i4 0 ldsfld <Module>{6d9d8a6d-70ec-4c85-ac66-327556108fee} <Module>{6d9d8a6d-70ec-4c85-ac66-327556108fee}::m_f9533508d37249a1856916e014ee130b ldfld System.Int32 <Module>{6d9d8a6d-70ec-4c85-ac66-327556108fee}::m_6f300155b5724d22a7694aeed8aee7ab brtrue IL_0012: switch(IL_0024,IL_0025) pop <null> ldc.i4 0 br IL_0012: switch(IL_0024,IL_0025)

c34be59dd65449f1f59567c0649d6903 (3.52 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙