Suspicious
Suspect

c8943a082c2ec80f5f9f784a07841cd6

PE Executable
MD5: c8943a082c2ec80f5f9f784a07841cd6
Size: 932.35 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 c8943a082c2ec80f5f9f784a07841cd6
Sha1 0af7ede2be3c8ec8384031b02a811571bcda8843
Sha256 6175e1fc7dbe89153b7138bffb8292811014b18d8c82684cd4cf27e57ee4d580
Sha384 64fd8d06235a33fbdf8851388d120a09c5bc65253b5d2d5121f2c4595d567d2465460f0a09211d4537f6243967402d46
Sha512 6f43904db48e68fcab098240a3052de73dbc10e39e0f0699096c2d262a640dd2bb22127dd64451e70e4ae5d91012a879ad278e720c80aff805e393e0cd1bdbc4
SSDeep 24576:vFlHSQ0PYNIMuDzswXvSDeRzKTLAwl3hytu:d1S1sIWgWTLAwuu
TLSH 3E15CF9C3240F94FC857C9728964EDB4A6606C76930BC20395E76EEFBA1D687DF041E2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BatSonar.SchlafplatzForm.resources
BatSonar.Properties.Resources.resources
CxTp
[NBF]root.Data
[NBF]root.Data-preview.png
Map2026
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
HNYO.exe
Full Name
HNYO.exe
EntryPoint
System.Void BatSonar.Program::Main()
Scope Name
HNYO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
HNYO
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
0
Main Method
System.Void BatSonar.Program::Main()
Main IL Instruction Count
31
Main IL
nop <null>
ldc.i4 -301485092
ldc.i4 -591573089
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.4 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0052: newobj System.Void BatSonar.MigrationsForm::.ctor()
call System.Void BatSonar.Program::‎‭‏‭‏‭‫‎‬‌​‌‏‫‬‏‭‬‭‌‬‪‫‌‫‎‌‬‮()
ldloc.0 <null>
ldc.i4 1472156623
mul <null>
ldc.i4 81596456
xor <null>
br.s IL_0006: ldc.i4 -591573089
nop <null>
ldc.i4.0 <null>
call System.Void BatSonar.Program::‌‎‏‫‮‬‎‌‏‏‮‬‮‬‍‎‪‏​‌‮‪‬‌‮(System.Boolean)
nop <null>
ldloc.0 <null>
ldc.i4 -790729452
mul <null>
ldc.i4 -748157226
xor <null>
br.s IL_0006: ldc.i4 -591573089
newobj System.Void BatSonar.MigrationsForm::.ctor()
call System.Void BatSonar.Program::​‫‮‫‪​‬‌‫‭‫‎‏‎‬‎‌‪‬‭​‮​‍‌‭‮(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
HNYO.exe
Full Name
HNYO.exe
EntryPoint
System.Void BatSonar.Program::Main()
Scope Name
HNYO.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
HNYO
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
0
Main Method
System.Void BatSonar.Program::Main()
Main IL Instruction Count
31
Main IL
nop <null>
ldc.i4 -301485092
ldc.i4 -591573089
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.4 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_0052: newobj System.Void BatSonar.MigrationsForm::.ctor()
call System.Void BatSonar.Program::‎‭‏‭‏‭‫‎‬‌​‌‏‫‬‏‭‬‭‌‬‪‫‌‫‎‌‬‮()
ldloc.0 <null>
ldc.i4 1472156623
mul <null>
ldc.i4 81596456
xor <null>
br.s IL_0006: ldc.i4 -591573089
nop <null>
ldc.i4.0 <null>
call System.Void BatSonar.Program::‌‎‏‫‮‬‎‌‏‏‮‬‮‬‍‎‪‏​‌‮‪‬‌‮(System.Boolean)
nop <null>
ldloc.0 <null>
ldc.i4 -790729452
mul <null>
ldc.i4 -748157226
xor <null>
br.s IL_0006: ldc.i4 -591573089
newobj System.Void BatSonar.MigrationsForm::.ctor()
call System.Void BatSonar.Program::​‫‮‫‪​‬‌‫‭‫‎‏‎‬‎‌‪‬‭​‮​‍‌‭‮(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
BatSonar.SchlafplatzForm.resources
BatSonar.Properties.Resources.resources
CxTp
[NBF]root.Data
[NBF]root.Data-preview.png
Map2026
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙