Suspicious
Suspect

PE Executable
MD5: ced43def9e74d6f1871d55939711895a
Size: 2.63 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 ced43def9e74d6f1871d55939711895a
Sha1 71f2771214d30adcc03fbeec803f4abe5f6cf7d3
Sha256 217cdab58a3e360e4d94cee5cb4e8cb3189f717171c38d07285314805320059d
Sha384 a2851f7704d2904f8728866845c8b004a8910a267cd3ebddd860dfb7b0542afe09af65886d7892310595c3dd2b0db6a0
Sha512 7c35946bd6a82e922e1a6f251f74ac6af5f17e1c9dff6425e9918c1daa4ab556aa9e6cd8c6fed91b235b6971e4d78a4350d1a62fbe1fc189f98a2d6426bdf00e
SSDeep 49152:JOyIrtc4Lo9YYR0BJJTpc8iYMCJzBWENRrFX2pVCdAksnWCp2XCkl:Iv9HTFMCzjNlJisdAksFk
TLSH D5C50143F28548AAC06F157EA6F01720E3EB2920E775C7EED1D02E6CD961484AA73797
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ikeCEjFwePL8.CJFok3Bc.nur
qftEKiM.bat
7z-stream @ 0x000C6D78.7z
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.sxdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
.rsrc
Resources
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
Resources
RT_CURSOR
ID:0001
ID:1033
RT_DIALOG
ID:0066
ID:1037
ID:0070
ID:1037
RT_GROUP_CURSOR2
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1037
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
STRING
ID:07D1
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
ID:07D2
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
ID:07D3
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0-preview.png
RT_DIALOG
ID:0069
ID:0
ID:0084
ID:0
RT_GROUP_CURSOR4
ID:07D0
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.didat
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_MANIFEST
ID:0001
ID:1033
             
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
DownloaderApp.exe
Full Name
DownloaderApp.exe
EntryPoint
System.Void  ::(System.String[])
Scope Name
DownloaderApp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DownloaderApp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
0
Main Method
System.Void  ::(System.String[])
Main IL Instruction Count
62
Main IL
call System.Boolean  ::()
brtrue.s IL_0015: call System.Boolean System.Environment::get_UserInteractive()
call System.Void  ::()
leave.s IL_0014: ret
pop <null>
leave IL_00C1: ret
ret <null>
call System.Boolean System.Environment::get_UserInteractive()
brtrue.s IL_0027: ldc.i4 192762813
newobj System.Void  ::.ctor()
call System.Void System.ServiceProcess.ServiceBase::Run(System.ServiceProcess.ServiceBase)
ret <null>
ldc.i4 192762813
call System.String  ::(System.Int32)
stloc.2 <null>
ldc.i4 192762879
call System.String  ::(System.Int32)
stloc.3 <null>
ldc.i4 192762836
call System.String  ::(System.Int32)
stloc.s V_4
ldc.i4.s 36
call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder)
dup <null>
ldloc.2 <null>
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.0 <null>
ldloc.3 <null>
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.1 <null>
ldc.i4 192762783
call System.String  ::(System.Int32)
ldloc.0 <null>
call System.Void  ::(System.String,System.String)
ldc.i4 192762668
call System.String  ::(System.Int32)
ldloc.1 <null>
call System.Void  ::(System.String,System.String)
ldloc.0 <null>
ldc.i4.6 <null>
call System.Void System.IO.File::SetAttributes(System.String,System.IO.FileAttributes)
ldloc.1 <null>
ldc.i4.6 <null>
call System.Void System.IO.File::SetAttributes(System.String,System.IO.FileAttributes)
ldloc.0 <null>
call System.Void  ::(System.String)
ldloc.1 <null>
call System.Void  ::(System.String)
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
callvirt System.String System.Reflection.Assembly::get_Location()
call System.Void  ::(System.String)
ldloc.0 <null>
ldloc.s V_4
call System.Void  ::(System.String,System.String)
ldloc.0 <null>
call System.Void  ::(System.String)
ldloc.1 <null>
call System.Void  ::(System.String)
leave.s IL_00C1: ret
pop <null>
leave.s IL_00C1: ret
ret <null>
Module Name
DownloaderApp.exe
Full Name
DownloaderApp.exe
EntryPoint
System.Void  ::(System.String[])
Scope Name
DownloaderApp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DownloaderApp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
0
Main Method
System.Void  ::(System.String[])
Main IL Instruction Count
62
Main IL
call System.Boolean  ::()
brtrue.s IL_0015: call System.Boolean System.Environment::get_UserInteractive()
call System.Void  ::()
leave.s IL_0014: ret
pop <null>
leave IL_00C1: ret
ret <null>
call System.Boolean System.Environment::get_UserInteractive()
brtrue.s IL_0027: ldc.i4 192762813
newobj System.Void  ::.ctor()
call System.Void System.ServiceProcess.ServiceBase::Run(System.ServiceProcess.ServiceBase)
ret <null>
ldc.i4 192762813
call System.String  ::(System.Int32)
stloc.2 <null>
ldc.i4 192762879
call System.String  ::(System.Int32)
stloc.3 <null>
ldc.i4 192762836
call System.String  ::(System.Int32)
stloc.s V_4
ldc.i4.s 36
call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder)
dup <null>
ldloc.2 <null>
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.0 <null>
ldloc.3 <null>
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.1 <null>
ldc.i4 192762783
call System.String  ::(System.Int32)
ldloc.0 <null>
call System.Void  ::(System.String,System.String)
ldc.i4 192762668
call System.String  ::(System.Int32)
ldloc.1 <null>
call System.Void  ::(System.String,System.String)
ldloc.0 <null>
ldc.i4.6 <null>
call System.Void System.IO.File::SetAttributes(System.String,System.IO.FileAttributes)
ldloc.1 <null>
ldc.i4.6 <null>
call System.Void System.IO.File::SetAttributes(System.String,System.IO.FileAttributes)
ldloc.0 <null>
call System.Void  ::(System.String)
ldloc.1 <null>
call System.Void  ::(System.String)
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
callvirt System.String System.Reflection.Assembly::get_Location()
call System.Void  ::(System.String)
ldloc.0 <null>
ldloc.s V_4
call System.Void  ::(System.String,System.String)
ldloc.0 <null>
call System.Void  ::(System.String)
ldloc.1 <null>
call System.Void  ::(System.String)
leave.s IL_00C1: ret
pop <null>
leave.s IL_00C1: ret
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ikeCEjFwePL8.CJFok3Bc.nur
qftEKiM.bat
7z-stream @ 0x000C6D78.7z
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.sxdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
.rsrc
Resources
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
Resources
RT_CURSOR
ID:0001
ID:1033
RT_DIALOG
ID:0066
ID:1037
ID:0070
ID:1037
RT_GROUP_CURSOR2
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1037
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
STRING
ID:07D1
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
ID:07D2
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
ID:07D3
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0-preview.png
RT_DIALOG
ID:0069
ID:0
ID:0084
ID:0
RT_GROUP_CURSOR4
ID:07D0
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.didat
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_MANIFEST
ID:0001
ID:1033
             
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙