Suspicious
Suspect

c66e79a66089bd185b9297c769b78b94

PE Executable
|
MD5: c66e79a66089bd185b9297c769b78b94
|
Size: 2.16 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
c66e79a66089bd185b9297c769b78b94
Sha1
17efb386ba943aedd05db654614190399f2e97c1
Sha256
7cd0a6af118b9f762535e320a00aff5c3d9eb7d9f8575d37d366bac19298cd84
Sha384
e79c1e55792d08cd8765c07e1a51212eb878d85bb9cad175a73db34f43f7f1100c5154d42d96e464dd14d21677099cf5
Sha512
fc883c40cd468fe9d18a9f189a78d7b8565c89cf097c3b7417ffeaec381a5bb14d286843baeeeb3bd209ad4d3eabb7ac752fe23687383c01690e7a521728471a
SSDeep
49152:ETmG0Y321BhdoJ8X5DL3tL/HO5xSD3WhG31q10+UbX12:W21rn9PUSD3mG3OpUZ
TLSH
D2A5BE05AAD55F53E2BA473788E3AA5473B6B892FB4BE74F514430A209053D34B036FB

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
{883aa2b0-a7e9-4c7b-b5d4-0f410d0f21be}
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Ubngg.exe

Full Name

Ubngg.exe

EntryPoint

System.Void .::()

Scope Name

Ubngg.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Ubngg

Assembly Version

1.0.2999.15101

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1232

Main Method

System.Void .::()

Main IL Instruction Count

58

Main IL

br IL_008B: newobj System.Void .::.ctor() br IL_0095: stloc.0 br.s IL_005C: ldloc.0 br.s IL_005F: callvirt System.String .::() brfalse.s IL_005A: leave.s IL_008A br.s IL_0066: ldloc.0 br.s IL_0069: call System.Type[] .::(.) ldsfld System.Func`2<System.Type,System.Boolean> ./:: dup <null> brtrue.s IL_0033: br.s IL_0070 pop <null> ldsfld ./ ./:: ldftn System.Boolean ./::(System.Type) newobj System.Void System.Func`2<System.Type,System.Boolean>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Func`2<System.Type,System.Boolean> ./:: br.s IL_0070: call System.Collections.Generic.IEnumerable`1<System.Type> System.Linq.Enumerable::Where<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>,System.Func`2<System.Type,System.Boolean>) br.s IL_0077: stloc.1 br.s IL_007A: ldloc.1 call System.Int32 System.Linq.Enumerable::Count<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldc.i4.0 <null> ble.s IL_005A: leave.s IL_008A ldloc.1 <null> call System.Type System.Linq.Enumerable::First<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldstr oXkkS9fTY ldc.i4 256 ldnull <null> ldnull <null> ldnull <null> callvirt System.Object System.Type::InvokeMember(System.String,System.Reflection.BindingFlags,System.Reflection.Binder,System.Object,System.Object[]) pop <null> leave.s IL_008A: ret ldloc.0 <null> br.s IL_000C: br.s IL_005F callvirt System.String .::() br.s IL_000E: brfalse.s IL_005A ldloc.0 <null> br.s IL_0012: br.s IL_0069 call System.Type[] .::(.) br.s IL_0014: ldsfld System.Func`2<System.Type,System.Boolean> ./:: call System.Collections.Generic.IEnumerable`1<System.Type> System.Linq.Enumerable::Where<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>,System.Func`2<System.Type,System.Boolean>) br.s IL_0035: br.s IL_0077 stloc.1 <null> br.s IL_0037: br.s IL_007A ldloc.1 <null> br.s IL_0039: call System.Int32 System.Linq.Enumerable::Count<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldloc.0 <null> brfalse.s IL_0086: ldc.i4.3 ldloc.0 <null> callvirt System.Void System.IDisposable::Dispose() ldc.i4.3 <null> brfalse.s IL_007D: ldloc.0 endfinally <null> ret <null> newobj System.Void .::.ctor() br IL_0005: br IL_0095 stloc.0 <null> br IL_000A: br.s IL_005C

Module Name

Ubngg.exe

Full Name

Ubngg.exe

EntryPoint

System.Void .::()

Scope Name

Ubngg.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Ubngg

Assembly Version

1.0.2999.15101

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1232

Main Method

System.Void .::()

Main IL Instruction Count

58

Main IL

br IL_008B: newobj System.Void .::.ctor() br IL_0095: stloc.0 br.s IL_005C: ldloc.0 br.s IL_005F: callvirt System.String .::() brfalse.s IL_005A: leave.s IL_008A br.s IL_0066: ldloc.0 br.s IL_0069: call System.Type[] .::(.) ldsfld System.Func`2<System.Type,System.Boolean> ./:: dup <null> brtrue.s IL_0033: br.s IL_0070 pop <null> ldsfld ./ ./:: ldftn System.Boolean ./::(System.Type) newobj System.Void System.Func`2<System.Type,System.Boolean>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Func`2<System.Type,System.Boolean> ./:: br.s IL_0070: call System.Collections.Generic.IEnumerable`1<System.Type> System.Linq.Enumerable::Where<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>,System.Func`2<System.Type,System.Boolean>) br.s IL_0077: stloc.1 br.s IL_007A: ldloc.1 call System.Int32 System.Linq.Enumerable::Count<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldc.i4.0 <null> ble.s IL_005A: leave.s IL_008A ldloc.1 <null> call System.Type System.Linq.Enumerable::First<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldstr oXkkS9fTY ldc.i4 256 ldnull <null> ldnull <null> ldnull <null> callvirt System.Object System.Type::InvokeMember(System.String,System.Reflection.BindingFlags,System.Reflection.Binder,System.Object,System.Object[]) pop <null> leave.s IL_008A: ret ldloc.0 <null> br.s IL_000C: br.s IL_005F callvirt System.String .::() br.s IL_000E: brfalse.s IL_005A ldloc.0 <null> br.s IL_0012: br.s IL_0069 call System.Type[] .::(.) br.s IL_0014: ldsfld System.Func`2<System.Type,System.Boolean> ./:: call System.Collections.Generic.IEnumerable`1<System.Type> System.Linq.Enumerable::Where<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>,System.Func`2<System.Type,System.Boolean>) br.s IL_0035: br.s IL_0077 stloc.1 <null> br.s IL_0037: br.s IL_007A ldloc.1 <null> br.s IL_0039: call System.Int32 System.Linq.Enumerable::Count<System.Type>(System.Collections.Generic.IEnumerable`1<System.Type>) ldloc.0 <null> brfalse.s IL_0086: ldc.i4.3 ldloc.0 <null> callvirt System.Void System.IDisposable::Dispose() ldc.i4.3 <null> brfalse.s IL_007D: ldloc.0 endfinally <null> ret <null> newobj System.Void .::.ctor() br IL_0005: br IL_0095 stloc.0 <null> br IL_000A: br.s IL_005C

c66e79a66089bd185b9297c769b78b94 (2.16 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
{883aa2b0-a7e9-4c7b-b5d4-0f410d0f21be}
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙