Suspicious
Suspect

PE Executable
MD5: c644177d1eaf07bce855ddf14053d43a
Size: 747.01 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 c644177d1eaf07bce855ddf14053d43a
Sha1 59bb37df9c0bb7c29bf4ef247c6921f2c19e2cb3
Sha256 2ba41f387ea8d91674878017056d8653151a1c2bc45b4d4c4d97c83657b01db6
Sha384 2276ec98ab2fedec1337f23e697f907579a74666747ececf823a1a80538852efff24ac63d29bbb3a258c12c33525460e
Sha512 d32948f64996fdd34df736ed91f5559e1e92fdbaace6e3796d724ff304ebc473bddf6aad6d4f664672149f1788cbaf0b730ff10895232be089f7088a68a3de88
SSDeep 12288:T7Xg/Ofj9WnqE18YGZy7cAtNo4b4Wu8WWsNUnf9MNCmVLlMP2Y917l+bWB0hOY:TTHQqE18903tWQ4Ww9STmVLlg2Y91WW8
TLSH 31F4122CB765F991D61C0B77E423A10895B1085BF1B9F0AF64DA5CE10B29BC8866F7C3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Module Name
dOdd.exe
Full Name
dOdd.exe
EntryPoint
System.Void SecureMode.Program::Main()
Scope Name
dOdd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dOdd
Assembly Version
1.6.1908.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
2
Main Method
System.Void SecureMode.Program::Main()
Main IL Instruction Count
33
Main IL
ldc.i4.2 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void SecureMode.EnhancedForm12::Ⴍ()
ldc.i4 296
ldc.i4 374
call System.Void SecureMode.ReliableForm18::Ⴓ(System.Int32,System.Int16)
ldc.i4.0 <null>
ldc.i4 508
ldc.i4 396
call System.Void SecureMode.ProfessionalForm53::Ⴀ(System.Boolean,System.Int32,System.Int32)
ldc.i4.0 <null>
stloc.1 <null>
br.s IL_0002: ldloc.1
newobj System.Void SecureMode.ProfessionalForm53::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ldsfld System.Char[] SecureMode.EnhancedForm84::Ⴗ
ldc.i4.s 103
ldsfld System.Char[] SecureMode.EnhancedForm84::Ⴗ
ldc.i4.s 103
ldelem.u2 <null>
ldsfld System.Char[] SecureMode.EnhancedForm84::Ⴗ
ldc.i4.s 31
ldelem.u2 <null>
and <null>
ldc.i4 199
and <null>
stelem.i2 <null>
ret <null>
ldtoken System.Void SecureMode.Program::Main()
pop <null>
ret <null>
Module Name
dOdd.exe
Full Name
dOdd.exe
EntryPoint
System.Void SecureMode.Program::Main()
Scope Name
dOdd.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dOdd
Assembly Version
1.6.1908.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
2
Main Method
System.Void SecureMode.Program::Main()
Main IL Instruction Count
33
Main IL
ldc.i4.2 <null>
stloc.1 <null>
ldloc.1 <null>
switch dnlib.DotNet.Emit.Instruction[]
call System.Void SecureMode.EnhancedForm12::Ⴍ()
ldc.i4 296
ldc.i4 374
call System.Void SecureMode.ReliableForm18::Ⴓ(System.Int32,System.Int16)
ldc.i4.0 <null>
ldc.i4 508
ldc.i4 396
call System.Void SecureMode.ProfessionalForm53::Ⴀ(System.Boolean,System.Int32,System.Int32)
ldc.i4.0 <null>
stloc.1 <null>
br.s IL_0002: ldloc.1
newobj System.Void SecureMode.ProfessionalForm53::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ldsfld System.Char[] SecureMode.EnhancedForm84::Ⴗ
ldc.i4.s 103
ldsfld System.Char[] SecureMode.EnhancedForm84::Ⴗ
ldc.i4.s 103
ldelem.u2 <null>
ldsfld System.Char[] SecureMode.EnhancedForm84::Ⴗ
ldc.i4.s 31
ldelem.u2 <null>
and <null>
ldc.i4 199
and <null>
stelem.i2 <null>
ret <null>
ldtoken System.Void SecureMode.Program::Main()
pop <null>
ret <null>
Embedded Resources UNKNWOWN
0huhuhuhu
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
Embedded Resources UNKNWOWN
0huhuhuhu
c644177d1eaf07bce855ddf14053d43a
Suspicious Type Names (1-2 chars) UNKNWOWN
0huhuhuhu
c644177d1eaf07bce855ddf14053d43a
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙