Suspicious
Suspect

d0ae4494344a09e5591e190f8ece7c45

PE Executable
|
MD5: d0ae4494344a09e5591e190f8ece7c45
|
Size: 793.6 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
d0ae4494344a09e5591e190f8ece7c45
Sha1
6c974e5dada1d0dbbea5e55d7234005fe6a18b95
Sha256
f4862dbce922841b392d640cc9469fa48b53509cdd81ca783d851a7537b6478d
Sha384
9056a00f78ccdac260ad73094001fd963bbced6037ea05ced4ba9b997f829b909ee2b49900cc9f5128b7cd195eb813d6
Sha512
3fc1172bf3688808607ad30512e0cf3738244c4d9c41f02451b8b477a2c6f563204557ca6de321e913dbde66feea02ce6ce3952fe340faf136ea4b27be0ec20f
SSDeep
12288:qxp1iKbDNgFd/GxkAlJX5kcu+FdX1uxwWFEJjzuFxyLqZE4:gFgb/GiAljl1uxwWAjU24
TLSH
99F4AD6227E85B58F5BEAB3E657015014BF1FC16EB32EA1D3EA450DD0861F81C962B33

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Ginaporizan.6813905.png
6Fdcf2wX.Resources.resources
d0d1f34d13dca2.Resources.resources
829915dc0
[NBF]root.Data
829915dc1
[NBF]root.Data
829915dc2
[NBF]root.Data
829915dc3
[NBF]root.Data
829915dc4
[NBF]root.Data
829915dc5
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

6Fdcf2wX

Full Name

6Fdcf2wX

EntryPoint

System.Void 6Fdcf2wX.ye1R7jT::xRc36osHM2e()

Scope Name

6Fdcf2wX

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

6Fdcf2wX

Assembly Version

18.1.45.92

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1713

Main Method

System.Void 6Fdcf2wX.ye1R7jT::xRc36osHM2e()

Main IL Instruction Count

102

Main IL

nop <null> nop <null> ldloc.0 <null> newobj System.Void 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::.ctor(6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_) stloc.0 <null> ldloc.0 <null> ldc.i4.1 <null> stfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldc.i4.s 24 clt <null> stloc.s V_4 ldloc.s V_4 brfalse.s IL_0028: ldc.i4.1 ldloc.0 <null> ldc.i4.s 24 stfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldc.i4.1 <null> ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz conv.r8 <null> ldc.r8 24 div <null> call System.Double System.Math::Ceiling(System.Double) ldc.r8 1 add <null> call System.Double System.Math::Round(System.Double) conv.ovf.i4 <null> call System.Collections.Generic.IEnumerable`1<System.Int32> System.Linq.Enumerable::Range(System.Int32,System.Int32) ldsfld System.Func`2<System.Int32,System.Int32> 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::7dpHo9Kn5Aj brfalse.s IL_0062: ldsfld 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::j_8Bx0Jx ldsfld System.Func`2<System.Int32,System.Int32> 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::7dpHo9Kn5Aj br.s IL_0078: call System.Collections.Generic.IEnumerable`1<System.Int32> System.Linq.Enumerable::Select<System.Int32,System.Int32>(System.Collections.Generic.IEnumerable`1<System.Int32>,System.Func`2<System.Int32,System.Int32>) ldsfld 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::j_8Bx0Jx ldftn System.Int32 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::ri7ME3m(System.Int32) newobj System.Void System.Func`2<System.Int32,System.Int32>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Func`2<System.Int32,System.Int32> 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::7dpHo9Kn5Aj call System.Collections.Generic.IEnumerable`1<System.Int32> System.Linq.Enumerable::Select<System.Int32,System.Int32>(System.Collections.Generic.IEnumerable`1<System.Int32>,System.Func`2<System.Int32,System.Int32>) call System.Int32[] System.Linq.Enumerable::ToArray<System.Int32>(System.Collections.Generic.IEnumerable`1<System.Int32>) stloc.1 <null> ldloc.0 <null> ldloc.1 <null> ldloc.0 <null> ldftn System.Boolean 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::4gpEe2(System.Int32) newobj System.Void System.Func`2<System.Int32,System.Boolean>::.ctor(System.Object,System.IntPtr) call System.Int32 System.Linq.Enumerable::First<System.Int32>(System.Collections.Generic.IEnumerable`1<System.Int32>,System.Func`2<System.Int32,System.Boolean>) stfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newarr System.Object stloc.2 <null> ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldc.i4.2 <null> sub.ovf <null> stloc.s V_5 ldc.i4.0 <null> stloc.s V_6 br.s IL_00C5: ldloc.s V_6 ldloc.2 <null> ldloc.s V_6 ldnull <null> stelem.ref <null> ldloc.s V_6 ldc.i4.1 <null> add.ovf <null> stloc.s V_6 ldloc.s V_6 ldloc.s V_5 ble.s IL_00BA: ldloc.2 ldstr gnp.5093186 call System.String Microsoft.VisualBasic.Strings::StrReverse(System.String) stloc.3 <null> ldloc.2 <null> ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldc.i4.1 <null> sub.ovf <null> ldloc.3 <null> call System.Byte[] 6Fdcf2wX.2FreJfy3::3tyXqS9xL(System.Object) call System.Byte[] 6Fdcf2wX.8diMK1b_p::jo4KCx(System.Byte[]) stelem.ref <null> ldloc.2 <null> ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz call System.Void 6Fdcf2wX.1xgWKw2kd0Ep3z::7cfSA2qy(System.Object[],System.Int32) nop <null> leave.s IL_010A: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_7 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_010A: nop nop <null> ret <null>

Module Name

6Fdcf2wX

Full Name

6Fdcf2wX

EntryPoint

System.Void 6Fdcf2wX.ye1R7jT::xRc36osHM2e()

Scope Name

6Fdcf2wX

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

6Fdcf2wX

Assembly Version

18.1.45.92

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

1713

Main Method

System.Void 6Fdcf2wX.ye1R7jT::xRc36osHM2e()

Main IL Instruction Count

102

Main IL

nop <null> nop <null> ldloc.0 <null> newobj System.Void 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::.ctor(6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_) stloc.0 <null> ldloc.0 <null> ldc.i4.1 <null> stfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldc.i4.s 24 clt <null> stloc.s V_4 ldloc.s V_4 brfalse.s IL_0028: ldc.i4.1 ldloc.0 <null> ldc.i4.s 24 stfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldc.i4.1 <null> ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz conv.r8 <null> ldc.r8 24 div <null> call System.Double System.Math::Ceiling(System.Double) ldc.r8 1 add <null> call System.Double System.Math::Round(System.Double) conv.ovf.i4 <null> call System.Collections.Generic.IEnumerable`1<System.Int32> System.Linq.Enumerable::Range(System.Int32,System.Int32) ldsfld System.Func`2<System.Int32,System.Int32> 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::7dpHo9Kn5Aj brfalse.s IL_0062: ldsfld 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::j_8Bx0Jx ldsfld System.Func`2<System.Int32,System.Int32> 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::7dpHo9Kn5Aj br.s IL_0078: call System.Collections.Generic.IEnumerable`1<System.Int32> System.Linq.Enumerable::Select<System.Int32,System.Int32>(System.Collections.Generic.IEnumerable`1<System.Int32>,System.Func`2<System.Int32,System.Int32>) ldsfld 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::j_8Bx0Jx ldftn System.Int32 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::ri7ME3m(System.Int32) newobj System.Void System.Func`2<System.Int32,System.Int32>::.ctor(System.Object,System.IntPtr) dup <null> stsfld System.Func`2<System.Int32,System.Int32> 6Fdcf2wX.ye1R7jT/8syWxJ4wXqg97a.wQw8tr4B1fE::7dpHo9Kn5Aj call System.Collections.Generic.IEnumerable`1<System.Int32> System.Linq.Enumerable::Select<System.Int32,System.Int32>(System.Collections.Generic.IEnumerable`1<System.Int32>,System.Func`2<System.Int32,System.Int32>) call System.Int32[] System.Linq.Enumerable::ToArray<System.Int32>(System.Collections.Generic.IEnumerable`1<System.Int32>) stloc.1 <null> ldloc.0 <null> ldloc.1 <null> ldloc.0 <null> ldftn System.Boolean 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::4gpEe2(System.Int32) newobj System.Void System.Func`2<System.Int32,System.Boolean>::.ctor(System.Object,System.IntPtr) call System.Int32 System.Linq.Enumerable::First<System.Int32>(System.Collections.Generic.IEnumerable`1<System.Int32>,System.Func`2<System.Int32,System.Boolean>) stfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newarr System.Object stloc.2 <null> ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldc.i4.2 <null> sub.ovf <null> stloc.s V_5 ldc.i4.0 <null> stloc.s V_6 br.s IL_00C5: ldloc.s V_6 ldloc.2 <null> ldloc.s V_6 ldnull <null> stelem.ref <null> ldloc.s V_6 ldc.i4.1 <null> add.ovf <null> stloc.s V_6 ldloc.s V_6 ldloc.s V_5 ble.s IL_00BA: ldloc.2 ldstr gnp.5093186 call System.String Microsoft.VisualBasic.Strings::StrReverse(System.String) stloc.3 <null> ldloc.2 <null> ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz ldc.i4.1 <null> sub.ovf <null> ldloc.3 <null> call System.Byte[] 6Fdcf2wX.2FreJfy3::3tyXqS9xL(System.Object) call System.Byte[] 6Fdcf2wX.8diMK1b_p::jo4KCx(System.Byte[]) stelem.ref <null> ldloc.2 <null> ldloc.0 <null> ldfld System.Int32 6Fdcf2wX.ye1R7jT/9Pgapw0Fq6.1pmTS5z_::2orZE0wz call System.Void 6Fdcf2wX.1xgWKw2kd0Ep3z::7cfSA2qy(System.Object[],System.Int32) nop <null> leave.s IL_010A: nop dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.s V_7 nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_010A: nop nop <null> ret <null>

d0ae4494344a09e5591e190f8ece7c45 (793.6 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Ginaporizan.6813905.png
6Fdcf2wX.Resources.resources
d0d1f34d13dca2.Resources.resources
829915dc0
[NBF]root.Data
829915dc1
[NBF]root.Data
829915dc2
[NBF]root.Data
829915dc3
[NBF]root.Data
829915dc4
[NBF]root.Data
829915dc5
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙