Suspicious
Suspect

c981b8144e2aebd6080858b04af3b600

Share on LinkedIn
Print
PE Executable
MD5: c981b8144e2aebd6080858b04af3b600
Size: 939.52 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 c981b8144e2aebd6080858b04af3b600
Sha1 4840c94508f6f9ebbd7389aa7e53a3436bb0d0c0
Sha256 dbd4edd258813db2cac4abddb2a4230b62874591c09daa6ffbcd5c9022ebd042
Sha384 6a747eef76fa0f01aeda9e275d725b737d19ff836d846b4db7bc456f69c3c4c3f78bae72c9b2e31a32c149b4c24fb17c
Sha512 f02101668c362ac241fa7285aba9c73ee46404ce47ec802819090fb61e9124e237c0af32c8e5da0217742ce4bbd9ed6396cc587220ee1ae39f1dd693f052777d
SSDeep 12288:W1kJXxY9bXvXAdpr+8Esd4sEwRA8DX2YI1Qsc6F3lrK/CDS:0exAIdZ+8EsdfRA8DXsjF3le
TLSH B815E0615EA726B5E89C0B78C023089C33F4E4071166DB6F0FED84F5AFAAF96D917850
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Ⴓ.ai1Z0tF.resources
0Lzgk1Mr.g.resources
c363278114c850.Resources.resources
0e6d358a0
[NBF]root.Data
0e6d358a1
[NBF]root.Data
0e6d358a10
[NBF]root.Data
0e6d358a11
[NBF]root.Data
0e6d358a12
[NBF]root.Data
0e6d358a13
[NBF]root.Data
0e6d358a14
[NBF]root.Data
0e6d358a15
[NBF]root.Data
0e6d358a16
[NBF]root.Data
0e6d358a17
[NBF]root.Data
0e6d358a18
[NBF]root.Data
0e6d358a19
[NBF]root.Data
0e6d358a2
[NBF]root.Data
0e6d358a20
[NBF]root.Data
0e6d358a21
[NBF]root.Data
0e6d358a22
[NBF]root.Data
0e6d358a23
[NBF]root.Data
0e6d358a3
[NBF]root.Data
0e6d358a4
[NBF]root.Data
0e6d358a5
[NBF]root.Data
0e6d358a6
[NBF]root.Data
0e6d358a7
[NBF]root.Data
0e6d358a8
[NBF]root.Data
0e6d358a9
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
0Lzgk1Mr
Full Name
0Lzgk1Mr
EntryPoint
System.Void Mks6s9N.ai1Z0tF/Jqt84sH.7jeZXo3::Pw3if9RamFx7()
Scope Name
0Lzgk1Mr
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
0Lzgk1Mr
Assembly Version
9.7.30.155
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void Mks6s9N.ai1Z0tF/Jqt84sH.7jeZXo3::Pw3if9RamFx7()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void Cw4w3TdgWid.tr7SWnz3::.ctor()
stloc.0 <null>
ret <null>
ldtoken System.Void Mks6s9N.ai1Z0tF/Jqt84sH.7jeZXo3::Pw3if9RamFx7()
pop <null>
ret <null>
Module Name
0Lzgk1Mr
Full Name
0Lzgk1Mr
EntryPoint
System.Void Mks6s9N.ai1Z0tF/Jqt84sH.7jeZXo3::Pw3if9RamFx7()
Scope Name
0Lzgk1Mr
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
0Lzgk1Mr
Assembly Version
9.7.30.155
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void Mks6s9N.ai1Z0tF/Jqt84sH.7jeZXo3::Pw3if9RamFx7()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void Cw4w3TdgWid.tr7SWnz3::.ctor()
stloc.0 <null>
ret <null>
ldtoken System.Void Mks6s9N.ai1Z0tF/Jqt84sH.7jeZXo3::Pw3if9RamFx7()
pop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙