Suspicious
Suspect

PE Executable
MD5: cdd42dc7fde55600b226f27181d96120
Size: 926.21 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 cdd42dc7fde55600b226f27181d96120
Sha1 5e0a84a5208366f86671eef7699c3f22f6dbc07a
Sha256 2a084e79463e72c0933ec50e0b89aa2cdd5295584b6d6b211da98c5a3b4a8a8c
Sha384 e41b2ec8be5b78fe562dc614d5db9527e8cb1559421b5f16b6fd0ac2c5d1380238b6525c6fe4b62879b9916b61e87733
Sha512 9e1b8ae0e0df14bb229d5defde13e9e92822db50ea264d646f91df9bc3f4f1eb644b6a43a472813f82ad7470aff11c333cc92f24761deab9e858ffa12fd5cff7
SSDeep 24576:s/3l0VmLLduFe6S2rn9RUsc1K7NLoGo0c53:4emEa1ALvM
TLSH FC15CF012BF84A98F5BF97399D311A1487F5F803CB36DB1E2D9850EE1962F819961373
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Pobregas.67594
Dme5ec7Q.Resources.resources
f7177e680635d0.Resources.resources
071bc7580
[NBF]root.Data
071bc7581
[NBF]root.Data
071bc75810
[NBF]root.Data
071bc75811
[NBF]root.Data
071bc75812
[NBF]root.Data
071bc75813
[NBF]root.Data
071bc75814
[NBF]root.Data
071bc75815
[NBF]root.Data
071bc75816
[NBF]root.Data
071bc75817
[NBF]root.Data
071bc75818
[NBF]root.Data
071bc75819
[NBF]root.Data
071bc7582
[NBF]root.Data
071bc75820
[NBF]root.Data
071bc7583
[NBF]root.Data
071bc7584
[NBF]root.Data
071bc7585
[NBF]root.Data
071bc7586
[NBF]root.Data
071bc7587
[NBF]root.Data
071bc7588
[NBF]root.Data
071bc7589
[NBF]root.Data
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Dme5ec7Q
Full Name
Dme5ec7Q
EntryPoint
System.Void Dme5ec7Q.7Ftfw::Ksn04z()
Scope Name
Dme5ec7Q
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Dme5ec7Q
Assembly Version
24.21.6.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1427
Main Method
System.Void Dme5ec7Q.7Ftfw::Ksn04z()
Main IL Instruction Count
24
Main IL
nop <null>
ldstr BackgroundService
stloc.0 <null>
ldc.i4 70193
stloc.1 <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.s 50
call System.Void System.Threading.Thread::Sleep(System.Int32)
nop <null>
nop <null>
ldstr 67594
call System.Void Dme5ec7Q.rXd3r0N/Yy7f2.7Zxnbj0YCmm::5MicEzw(System.String)
nop <null>
leave.s IL_003D: nop
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_003D: nop
nop <null>
ret <null>
Module Name
Dme5ec7Q
Full Name
Dme5ec7Q
EntryPoint
System.Void Dme5ec7Q.7Ftfw::Ksn04z()
Scope Name
Dme5ec7Q
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Dme5ec7Q
Assembly Version
24.21.6.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1427
Main Method
System.Void Dme5ec7Q.7Ftfw::Ksn04z()
Main IL Instruction Count
24
Main IL
nop <null>
ldstr BackgroundService
stloc.0 <null>
ldc.i4 70193
stloc.1 <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.s 50
call System.Void System.Threading.Thread::Sleep(System.Int32)
nop <null>
nop <null>
ldstr 67594
call System.Void Dme5ec7Q.rXd3r0N/Yy7f2.7Zxnbj0YCmm::5MicEzw(System.String)
nop <null>
leave.s IL_003D: nop
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_003D: nop
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Pobregas.67594
Dme5ec7Q.Resources.resources
f7177e680635d0.Resources.resources
071bc7580
[NBF]root.Data
071bc7581
[NBF]root.Data
071bc75810
[NBF]root.Data
071bc75811
[NBF]root.Data
071bc75812
[NBF]root.Data
071bc75813
[NBF]root.Data
071bc75814
[NBF]root.Data
071bc75815
[NBF]root.Data
071bc75816
[NBF]root.Data
071bc75817
[NBF]root.Data
071bc75818
[NBF]root.Data
071bc75819
[NBF]root.Data
071bc7582
[NBF]root.Data
071bc75820
[NBF]root.Data
071bc7583
[NBF]root.Data
071bc7584
[NBF]root.Data
071bc7585
[NBF]root.Data
071bc7586
[NBF]root.Data
071bc7587
[NBF]root.Data
071bc7588
[NBF]root.Data
071bc7589
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙