Suspicious
Suspect

PE Executable
MD5: c9f0f5c54927915dfa5be5898e7afde0
Size: 459.26 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 c9f0f5c54927915dfa5be5898e7afde0
Sha1 8ca33f8f3097d3c3d8d005c0f0060ea9606f93a7
Sha256 4206c4ded33b3137cb67d2013deb8c6d78b4a55fd16d9930904ad548d8802c19
Sha384 6d70ac42ba11e375fa2d347e704647ac9f27ddee7602589b2f8f9b1220a8e4c256ea803e905e87a76eeb1e7eaf67bc02
Sha512 aff619924e5fe804c1cbe73bbc3bdc2f0d66589b535a681ffe5a12f914aea3af1cc67937c362df6f94239937e16aac2eec3d4fca8a734c3fda60b4e0b46d2739
SSDeep 6144:it9Im+XtFgYKXkep2sNbq4TydaFJ1a0nAKVpROuZKcuWr4C4QcdugZAaqy+sDG:it9kdFgX52Ybv2daD1xAKrROu+T
TLSH 01A49D2027E85A55F1BFA779897105258BF1FC13D732E76EAA94409E0D72B80CE27723
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Rz0o2kmFw7Qxi.g.resources
Rz0o2kmFw7Qxi.Resources.resources
eddf874b3e762b.Resources.resources
d3fc9c310
[NBF]root.Data
d3fc9c311
[NBF]root.Data
d3fc9c312
[NBF]root.Data
d3fc9c313
[NBF]root.Data
d3fc9c314
[NBF]root.Data
d3fc9c315
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Rz0o2kmFw7Qxi
Full Name
Rz0o2kmFw7Qxi
EntryPoint
System.Void Rz0o2kmFw7Qxi.dy9F2Ng/Ze2bf1Nf5Gte.3pkGi0XeoFt::Ee5j_()
Scope Name
Rz0o2kmFw7Qxi
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Rz0o2kmFw7Qxi
Assembly Version
5.2.23.112
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1253
Main Method
System.Void Rz0o2kmFw7Qxi.dy9F2Ng/Ze2bf1Nf5Gte.3pkGi0XeoFt::Ee5j_()
Main IL Instruction Count
22
Main IL
nop <null>
call System.Threading.Thread System.Threading.Thread::get_CurrentThread()
call System.Globalization.CultureInfo System.Globalization.CultureInfo::get_InvariantCulture()
callvirt System.Void System.Threading.Thread::set_CurrentCulture(System.Globalization.CultureInfo)
nop <null>
call System.Threading.Thread System.Threading.Thread::get_CurrentThread()
call System.Globalization.CultureInfo System.Globalization.CultureInfo::get_InvariantCulture()
callvirt System.Void System.Threading.Thread::set_CurrentUICulture(System.Globalization.CultureInfo)
nop <null>
nop <null>
call System.Void Rz0o2kmFw7Qxi.dy9F2Ng::Zkk4dg0KW8tjyG()
nop <null>
leave.s IL_0037: nop
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0037: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
ret <null>
Module Name
Rz0o2kmFw7Qxi
Full Name
Rz0o2kmFw7Qxi
EntryPoint
System.Void Rz0o2kmFw7Qxi.dy9F2Ng/Ze2bf1Nf5Gte.3pkGi0XeoFt::Ee5j_()
Scope Name
Rz0o2kmFw7Qxi
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Rz0o2kmFw7Qxi
Assembly Version
5.2.23.112
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1253
Main Method
System.Void Rz0o2kmFw7Qxi.dy9F2Ng/Ze2bf1Nf5Gte.3pkGi0XeoFt::Ee5j_()
Main IL Instruction Count
22
Main IL
nop <null>
call System.Threading.Thread System.Threading.Thread::get_CurrentThread()
call System.Globalization.CultureInfo System.Globalization.CultureInfo::get_InvariantCulture()
callvirt System.Void System.Threading.Thread::set_CurrentCulture(System.Globalization.CultureInfo)
nop <null>
call System.Threading.Thread System.Threading.Thread::get_CurrentThread()
call System.Globalization.CultureInfo System.Globalization.CultureInfo::get_InvariantCulture()
callvirt System.Void System.Threading.Thread::set_CurrentUICulture(System.Globalization.CultureInfo)
nop <null>
nop <null>
call System.Void Rz0o2kmFw7Qxi.dy9F2Ng::Zkk4dg0KW8tjyG()
nop <null>
leave.s IL_0037: nop
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0037: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Rz0o2kmFw7Qxi.g.resources
Rz0o2kmFw7Qxi.Resources.resources
eddf874b3e762b.Resources.resources
d3fc9c310
[NBF]root.Data
d3fc9c311
[NBF]root.Data
d3fc9c312
[NBF]root.Data
d3fc9c313
[NBF]root.Data
d3fc9c314
[NBF]root.Data
d3fc9c315
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙