Malicious
Malicious

ca15094489ed6bebe84c22561cb74feb

PE Executable
|
MD5: ca15094489ed6bebe84c22561cb74feb
|
Size: 881.15 KB
|
application/x-dosexec


Print
General
Structural Analysis
Config.0
Yara Rules34
Sync
Community
Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
ca15094489ed6bebe84c22561cb74feb
Sha1
2e3f067865c5b15c96fc435be2d7838d3cc63121
Sha256
aeb87fa69750c8b7117ec7007727fbd11d6e385899074a964e6fef1e0f427cc1
Sha384
2bae83878fe37e8e349e9129fe9c4e5ca01722b97cdb600065a478d3389e8affab932cffc831b9a889b61729b52d3e77
Sha512
ace29cea834317643f49a3d7b0cfd05282cc2188f4562cfcf17e841bee1f1b53257c4088405d65d65a8171f72cd79f716bb9ac4e53b6b8aa5a931930d3bb85d6
SSDeep
12288:6KywR58MOQnnLgO2qzYV3CTOlkpzQyL4/FnQmQMLVYA7JQCxcIwX4WZoMvblbS6n:6rQLoo7mHQwA4WZoAoFm
TLSH
39153B07B64AC970E34987B2C49B148063E9D5C733ABDA4EBD8A13574D533BEF88524B

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
UPolyX 0.3 -> delikon
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Vm7VjnJvuUQsKFEuvf.xAHPjBK3Jbik99I7lY
hWQQW1FAiyy9qQFk1X.535dLmGdc3CgPiIdol
d1P3KbDSPW8KDTpxWg.0EiSbjE9nleLfRFk26
GYckIUBKLpRC9p1QFZ.gron73CdcXWhK7Gbrn
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

53A5CD8E8DCC175623036

Full Name

53A5CD8E8DCC175623036

EntryPoint

System.Void IEJAEJKFGOACAMHDNODBLDHPKADLKKOHCDHE.NOBLNNELCIHHEAONHHCLHLMHNPAOMKMELCAN::<Main>(System.String[])

Scope Name

53A5CD8E8DCC175623036

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

6B681338108892

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

44

Main Method

System.Void IEJAEJKFGOACAMHDNODBLDHPKADLKKOHCDHE.NOBLNNELCIHHEAONHHCLHLMHNPAOMKMELCAN::<Main>(System.String[])

Main IL Instruction Count

35

Main IL

ldc.i4 2 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_007C: ldloca.s V_1 ldarg.0 <null> call System.Threading.Tasks.Task IEJAEJKFGOACAMHDNODBLDHPKADLKKOHCDHE.NOBLNNELCIHHEAONHHCLHLMHNPAOMKMELCAN::JMCCOOPHNCFNEHPADILOIKGCFNHNAEBKLCAJ(System.Object) callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter() stloc.s V_1 ldc.i4 0 ldsfld <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f} <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_f4bdae30fda645efa4808c35809a4ea7 ldfld System.Int32 <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_cafa34694d4141f5b8745e5a595e31b6 brtrue IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) pop <null> ldc.i4 0 br IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) call System.Void IOIJJBNOGKNKIMGCMKIMAIACJKMHCNANONIF.KIDJLCNEDDPJGOMLDKMNAAMBBGHILJOOBMKH::kLjw4iIsCLsZtxc4lksN0j() ldc.i4 0 ldsfld <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f} <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_f4bdae30fda645efa4808c35809a4ea7 ldfld System.Int32 <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_c6eaa7a904384e2cb5e0a9e9bd252d91 brtrue IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) pop <null> ldc.i4 1 br IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) ldloca.s V_1 call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult() ldc.i4 3 ldsfld <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f} <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_f4bdae30fda645efa4808c35809a4ea7 ldfld System.Int32 <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_64898bb498144f80bc09767ba3f8a9ad brfalse IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) pop <null> ldc.i4 0 br IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) ret <null>

Module Name

53A5CD8E8DCC175623036

Full Name

53A5CD8E8DCC175623036

EntryPoint

System.Void IEJAEJKFGOACAMHDNODBLDHPKADLKKOHCDHE.NOBLNNELCIHHEAONHHCLHLMHNPAOMKMELCAN::<Main>(System.String[])

Scope Name

53A5CD8E8DCC175623036

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

6B681338108892

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.7.2

Total Strings

44

Main Method

System.Void IEJAEJKFGOACAMHDNODBLDHPKADLKKOHCDHE.NOBLNNELCIHHEAONHHCLHLMHNPAOMKMELCAN::<Main>(System.String[])

Main IL Instruction Count

35

Main IL

ldc.i4 2 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_007C: ldloca.s V_1 ldarg.0 <null> call System.Threading.Tasks.Task IEJAEJKFGOACAMHDNODBLDHPKADLKKOHCDHE.NOBLNNELCIHHEAONHHCLHLMHNPAOMKMELCAN::JMCCOOPHNCFNEHPADILOIKGCFNHNAEBKLCAJ(System.Object) callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter() stloc.s V_1 ldc.i4 0 ldsfld <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f} <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_f4bdae30fda645efa4808c35809a4ea7 ldfld System.Int32 <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_cafa34694d4141f5b8745e5a595e31b6 brtrue IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) pop <null> ldc.i4 0 br IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) call System.Void IOIJJBNOGKNKIMGCMKIMAIACJKMHCNANONIF.KIDJLCNEDDPJGOMLDKMNAAMBBGHILJOOBMKH::kLjw4iIsCLsZtxc4lksN0j() ldc.i4 0 ldsfld <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f} <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_f4bdae30fda645efa4808c35809a4ea7 ldfld System.Int32 <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_c6eaa7a904384e2cb5e0a9e9bd252d91 brtrue IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) pop <null> ldc.i4 1 br IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) ldloca.s V_1 call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult() ldc.i4 3 ldsfld <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f} <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_f4bdae30fda645efa4808c35809a4ea7 ldfld System.Int32 <Module>{5b5ee506-418c-40d6-a5d5-fc26f69dbc2f}::m_64898bb498144f80bc09767ba3f8a9ad brfalse IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) pop <null> ldc.i4 0 br IL_0012: switch(IL_007C,IL_002C,IL_0058,IL_00A2) ret <null>

ca15094489ed6bebe84c22561cb74feb (881.15 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙