Suspicious
Suspect

c7dafccc4f002c9fb5e7cd4975017f8f

PE Executable
|
MD5: c7dafccc4f002c9fb5e7cd4975017f8f
|
Size: 66.05 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Medium

Hash
Hash Value
MD5
c7dafccc4f002c9fb5e7cd4975017f8f
Sha1
2949c6873c5bfee95b569936156e73b05b459121
Sha256
8406ea30a5caf390fbf39c48e5d0dd87dc74224419351d18d482e82addc43dbc
Sha384
64ee5b247169622f7d12b7a1e0fe94dc0c3556ba8fbb350d6789acf6ae58b6e5abd1a9f8556b9369137fab3f5b609df3
Sha512
1e99438e235cf4807a83e0298a93bfcdb21028321d579af041bf5022bf7f82377c82f843db18e671d2213e51735514ef82fb8df022d83a08be375a376f6b7220
SSDeep
1536:8rH9YPA+m7rdoR0KayqPhta7y7ZEQeaxSFKc0oHY6I:8b9Y87rGzctauQun
TLSH
295319087789A233C76A477A88F5361443A0D0B7ADA1E3EF2DC27BD854DE7D8114ED86

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
fzIi
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Imjcppayee.exe

Full Name

Imjcppayee.exe

EntryPoint

System.Void Pztgutnhrqx.Ldeeuuitq::Main()

Scope Name

Imjcppayee.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Imjcppayee

Assembly Version

1.0.3259.19255

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

11

Main Method

System.Void Pztgutnhrqx.Ldeeuuitq::Main()

Main IL Instruction Count

193

Main IL

nop <null> ldc.i4 4032 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) br IL_0144: ldc.i4.s 99 nop <null> nop <null> ldsfld l[] l::e stloc.0 <null> br.s IL_001E: ldc.i4.s -111 ldnull <null> stloc.0 <null> br.s IL_0024: nop ldc.i4.s -111 ldc.i4.s -53 blt.s IL_001A: ldnull nop <null> leave.s IL_002C: ldc.i4 8573 pop <null> nop <null> nop <null> leave.s IL_002C: ldc.i4 8573 ldc.i4 8573 call System.String m::a(System.Int32) newobj System.Void System.Version::.ctor(System.String) stloc.1 <null> br IL_00DB: ldc.i4.s 117 ldloc.s V_8 ldc.i4.s 107 xor <null> stloc.s V_8 br.s IL_0081: ldc.i4.s 125 ldloc.s V_9 ldc.i4.s 103 xor <null> stloc.s V_9 br.s IL_0073: ldc.i4 135 ldloc.s V_10 ldc.i4 128 xor <null> stloc.s V_10 ldloc.s V_10 ldc.i4.s 125 add <null> switch dnlib.DotNet.Emit.Instruction[] ldc.i4 135 call System.Int32 c::a(System.Int32) stloc.s V_10 br.s IL_0053: ldloc.s V_10 ldc.i4.s 125 call System.Int32 c::a(System.Int32) stloc.s V_9 ldc.i4 -251 stloc.s V_10 br.s IL_0053: ldloc.s V_10 ldloc.s V_9 ldc.i4.s 125 add <null> switch dnlib.DotNet.Emit.Instruction[] ldc.i4 -253 stloc.s V_10 br.s IL_0053: ldloc.s V_10 br.s IL_004A: ldloc.s V_9 ldloc.s V_8 ldc.i4.s 110 sub <null> switch dnlib.DotNet.Emit.Instruction[] ldc.i4.s -29 stloc.s V_9 br IL_004A: ldloc.s V_9 ldc.i4.s 117 call System.Int32 i::e(System.Int32) stloc.s V_8 ldc.i4.s -30 stloc.s V_9 br IL_004A: ldloc.s V_9 br IL_0041: ldloc.s V_8 newobj System.Void i::.ctor() stloc.s V_4 ldc.i4.s 27 stloc.s V_8 br IL_0041: ldloc.s V_8 newobj System.Void h::.ctor() stloc.3 <null> ldc.i4.5 <null> stloc.s V_8 br IL_0041: ldloc.s V_8 newobj System.Void j::.ctor() stloc.s V_5 ldc.i4.s 25 stloc.s V_8 br IL_0041: ldloc.s V_8 ldnull <null> ldloc.1 <null> newobj System.Void g::.ctor(System.String,System.Version) stloc.2 <null> ldc.i4.s 57 call System.Int32 i::c(System.Int32) stloc.s V_8 br IL_0041: ldloc.s V_8 ldloc.3 <null> ldloc.s V_4 ldloc.s V_5 newobj System.Void k::.ctor(h,i,j) stloc.s V_6 br.s IL_014D: nop ldc.i4.s 99 ldc.i4.s 125 blt IL_0010: nop nop <null> ldloc.2 <null> ldloc.s V_6 ldftn System.Void k::a(System.Object,a) newobj System.Void System.EventHandler`1<a>::.ctor(System.Object,System.IntPtr) callvirt System.Void g::add_a(System.EventHandler`1<a>) br.s IL_01A0: ldc.i4.s 114 ldloc.s V_7 ldc.i4.s 97 xor <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 90 add <null> switch dnlib.DotNet.Emit.Instruction[] ldc.i4.s 114 call System.Int32 i::e(System.Int32) stloc.s V_7 br.s IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -52 stloc.s V_7 br.s IL_0163: ldloc.s V_7 ldloc.2 <null> callvirt System.Void g::a() ldc.i4.s -49 stloc.s V_7 br.s IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -58 stloc.s V_7 br.s IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -50 stloc.s V_7 br.s IL_0163: ldloc.s V_7 ldloc.s V_5 ldloc.s V_6 ldftn System.Void k::d(System.Object,d) newobj System.Void System.EventHandler`1<d>::.ctor(System.Object,System.IntPtr) callvirt System.Void j::add_a(System.EventHandler`1<d>) ldc.i4.s -55 stloc.s V_7 br IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -53 stloc.s V_7 br IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -47 stloc.s V_7 br IL_0163: ldloc.s V_7 ldloc.3 <null> ldloc.s V_6 ldftn System.Void k::b(System.Object,b) newobj System.Void System.EventHandler`1<b>::.ctor(System.Object,System.IntPtr) callvirt System.Void h::add_a(System.EventHandler`1<b>) ldc.i4.s -56 stloc.s V_7 br IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -51 stloc.s V_7 br IL_0163: ldloc.s V_7 ldloc.s V_4 ldloc.s V_6 ldftn System.Void k::c(System.Object,c) newobj System.Void System.EventHandler`1<c>::.ctor(System.Object,System.IntPtr) callvirt System.Void i::add_a(System.EventHandler`1<c>) ldc.i4.s -54 stloc.s V_7 br IL_0163: ldloc.s V_7 leave.s IL_0257: ret ldloc.s V_6 brfalse.s IL_0249: ldc.i4.1 ldc.i4.0 <null> br.s IL_024C: brtrue.s IL_0256 ldc.i4.1 <null> br.s IL_024C: brtrue.s IL_0256 brtrue.s IL_0256: endfinally ldloc.s V_6 callvirt System.Void System.IDisposable::Dispose() nop <null> endfinally <null> ret <null>

Module Name

Imjcppayee.exe

Full Name

Imjcppayee.exe

EntryPoint

System.Void Pztgutnhrqx.Ldeeuuitq::Main()

Scope Name

Imjcppayee.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Imjcppayee

Assembly Version

1.0.3259.19255

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

11

Main Method

System.Void Pztgutnhrqx.Ldeeuuitq::Main()

Main IL Instruction Count

193

Main IL

nop <null> ldc.i4 4032 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) br IL_0144: ldc.i4.s 99 nop <null> nop <null> ldsfld l[] l::e stloc.0 <null> br.s IL_001E: ldc.i4.s -111 ldnull <null> stloc.0 <null> br.s IL_0024: nop ldc.i4.s -111 ldc.i4.s -53 blt.s IL_001A: ldnull nop <null> leave.s IL_002C: ldc.i4 8573 pop <null> nop <null> nop <null> leave.s IL_002C: ldc.i4 8573 ldc.i4 8573 call System.String m::a(System.Int32) newobj System.Void System.Version::.ctor(System.String) stloc.1 <null> br IL_00DB: ldc.i4.s 117 ldloc.s V_8 ldc.i4.s 107 xor <null> stloc.s V_8 br.s IL_0081: ldc.i4.s 125 ldloc.s V_9 ldc.i4.s 103 xor <null> stloc.s V_9 br.s IL_0073: ldc.i4 135 ldloc.s V_10 ldc.i4 128 xor <null> stloc.s V_10 ldloc.s V_10 ldc.i4.s 125 add <null> switch dnlib.DotNet.Emit.Instruction[] ldc.i4 135 call System.Int32 c::a(System.Int32) stloc.s V_10 br.s IL_0053: ldloc.s V_10 ldc.i4.s 125 call System.Int32 c::a(System.Int32) stloc.s V_9 ldc.i4 -251 stloc.s V_10 br.s IL_0053: ldloc.s V_10 ldloc.s V_9 ldc.i4.s 125 add <null> switch dnlib.DotNet.Emit.Instruction[] ldc.i4 -253 stloc.s V_10 br.s IL_0053: ldloc.s V_10 br.s IL_004A: ldloc.s V_9 ldloc.s V_8 ldc.i4.s 110 sub <null> switch dnlib.DotNet.Emit.Instruction[] ldc.i4.s -29 stloc.s V_9 br IL_004A: ldloc.s V_9 ldc.i4.s 117 call System.Int32 i::e(System.Int32) stloc.s V_8 ldc.i4.s -30 stloc.s V_9 br IL_004A: ldloc.s V_9 br IL_0041: ldloc.s V_8 newobj System.Void i::.ctor() stloc.s V_4 ldc.i4.s 27 stloc.s V_8 br IL_0041: ldloc.s V_8 newobj System.Void h::.ctor() stloc.3 <null> ldc.i4.5 <null> stloc.s V_8 br IL_0041: ldloc.s V_8 newobj System.Void j::.ctor() stloc.s V_5 ldc.i4.s 25 stloc.s V_8 br IL_0041: ldloc.s V_8 ldnull <null> ldloc.1 <null> newobj System.Void g::.ctor(System.String,System.Version) stloc.2 <null> ldc.i4.s 57 call System.Int32 i::c(System.Int32) stloc.s V_8 br IL_0041: ldloc.s V_8 ldloc.3 <null> ldloc.s V_4 ldloc.s V_5 newobj System.Void k::.ctor(h,i,j) stloc.s V_6 br.s IL_014D: nop ldc.i4.s 99 ldc.i4.s 125 blt IL_0010: nop nop <null> ldloc.2 <null> ldloc.s V_6 ldftn System.Void k::a(System.Object,a) newobj System.Void System.EventHandler`1<a>::.ctor(System.Object,System.IntPtr) callvirt System.Void g::add_a(System.EventHandler`1<a>) br.s IL_01A0: ldc.i4.s 114 ldloc.s V_7 ldc.i4.s 97 xor <null> stloc.s V_7 ldloc.s V_7 ldc.i4.s 90 add <null> switch dnlib.DotNet.Emit.Instruction[] ldc.i4.s 114 call System.Int32 i::e(System.Int32) stloc.s V_7 br.s IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -52 stloc.s V_7 br.s IL_0163: ldloc.s V_7 ldloc.2 <null> callvirt System.Void g::a() ldc.i4.s -49 stloc.s V_7 br.s IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -58 stloc.s V_7 br.s IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -50 stloc.s V_7 br.s IL_0163: ldloc.s V_7 ldloc.s V_5 ldloc.s V_6 ldftn System.Void k::d(System.Object,d) newobj System.Void System.EventHandler`1<d>::.ctor(System.Object,System.IntPtr) callvirt System.Void j::add_a(System.EventHandler`1<d>) ldc.i4.s -55 stloc.s V_7 br IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -53 stloc.s V_7 br IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -47 stloc.s V_7 br IL_0163: ldloc.s V_7 ldloc.3 <null> ldloc.s V_6 ldftn System.Void k::b(System.Object,b) newobj System.Void System.EventHandler`1<b>::.ctor(System.Object,System.IntPtr) callvirt System.Void h::add_a(System.EventHandler`1<b>) ldc.i4.s -56 stloc.s V_7 br IL_0163: ldloc.s V_7 nop <null> ldc.i4.s -51 stloc.s V_7 br IL_0163: ldloc.s V_7 ldloc.s V_4 ldloc.s V_6 ldftn System.Void k::c(System.Object,c) newobj System.Void System.EventHandler`1<c>::.ctor(System.Object,System.IntPtr) callvirt System.Void i::add_a(System.EventHandler`1<c>) ldc.i4.s -54 stloc.s V_7 br IL_0163: ldloc.s V_7 leave.s IL_0257: ret ldloc.s V_6 brfalse.s IL_0249: ldc.i4.1 ldc.i4.0 <null> br.s IL_024C: brtrue.s IL_0256 ldc.i4.1 <null> br.s IL_024C: brtrue.s IL_0256 brtrue.s IL_0256: endfinally ldloc.s V_6 callvirt System.Void System.IDisposable::Dispose() nop <null> endfinally <null> ret <null>

c7dafccc4f002c9fb5e7cd4975017f8f (66.05 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
fzIi
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙