Malicious
Malicious

hyperbroker.exe

PE Executable
|
MD5: d665c5c267a9a308b2c3802314889acd
|
Size: 1.23 MB
|
application/x-dosexec


Print
General
Structural Analysis
Config.0
Yara Rules39
Sync
Community
Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
d665c5c267a9a308b2c3802314889acd
Sha1
71d8c5882d2ad8bbda653c74f80c9037a1ef4058
Sha256
36a0f0513068557e9637665a79dfa03c77fa71b0e084a6e386d8f671f4e6a3cf
Sha384
ef8ec85641a5992403953786768acce30247e66e60923419697e8f1b945d0d0dcd5490caa807ea92e9103a7d5feac80b
Sha512
0930073b8057756225555a541a9800a47a4f8a878492693d9a32e2195dd6a3cc0c59da8fadc26dd00afc63963ce75c80a179847e10378d13e8b0a92a3b8e64e3
SSDeep
24576:VzynWGhThz1lKI6pljZixqQDICTmqk43inoRYAA:4nnhR+lcTmz4yoR5
TLSH
F1455B057E48CE11F0291633C2FF454847B8AD526AA6E31B7DBA77AE15123A73C0D9CB

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
T5uusuyR4cdxr99t3T.mQxWaNbY9AyTco5uTV
xBueLOIgEoGXfp6Iyn.aCR9XT35Q3Nu4pqa0p
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

KDrUHOakinfdb2cAwypNbnA3bbooR7GYnvc0q

Full Name

KDrUHOakinfdb2cAwypNbnA3bbooR7GYnvc0q

EntryPoint

System.Void oT3xgfPmlQcXcFiAyqe.kJbw0XPb7CXG2Yxn0ET::y0rjOCNIls()

Scope Name

KDrUHOakinfdb2cAwypNbnA3bbooR7GYnvc0q

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

9Yvc7m6ygdktm3BnWgCy2qkwTkhHzp

Assembly Version

4.6.3.1

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

63

Main Method

System.Void oT3xgfPmlQcXcFiAyqe.kJbw0XPb7CXG2Yxn0ET::y0rjOCNIls()

Main IL Instruction Count

14

Main IL

br.s IL_000B: ldc.i4.0 call <null> ldnull <null> ldc.i4.0 <null> ldelem.ref <null> pop <null> ldc.i4.0 <null> brtrue.s IL_0007: ldnull call System.Void pZqXy64y77ATEQ2q2Ym.m1M41Q4ebLQQVqt2mtv::kLjw4iIsCLsZtxc4lksN0j() nop <null> ldsfld System.Object oT3xgfPmlQcXcFiAyqe.kJbw0XPb7CXG2Yxn0ET::CIWj4x1HTi callvirt System.Void rd1R1vPegCl1wu10V1g.snOQKDPYTkcX9ChY08T::DebYB92x5X() nop <null> ret <null>

Module Name

KDrUHOakinfdb2cAwypNbnA3bbooR7GYnvc0q

Full Name

KDrUHOakinfdb2cAwypNbnA3bbooR7GYnvc0q

EntryPoint

System.Void oT3xgfPmlQcXcFiAyqe.kJbw0XPb7CXG2Yxn0ET::y0rjOCNIls()

Scope Name

KDrUHOakinfdb2cAwypNbnA3bbooR7GYnvc0q

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

9Yvc7m6ygdktm3BnWgCy2qkwTkhHzp

Assembly Version

4.6.3.1

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

63

Main Method

System.Void oT3xgfPmlQcXcFiAyqe.kJbw0XPb7CXG2Yxn0ET::y0rjOCNIls()

Main IL Instruction Count

14

Main IL

br.s IL_000B: ldc.i4.0 call <null> ldnull <null> ldc.i4.0 <null> ldelem.ref <null> pop <null> ldc.i4.0 <null> brtrue.s IL_0007: ldnull call System.Void pZqXy64y77ATEQ2q2Ym.m1M41Q4ebLQQVqt2mtv::kLjw4iIsCLsZtxc4lksN0j() nop <null> ldsfld System.Object oT3xgfPmlQcXcFiAyqe.kJbw0XPb7CXG2Yxn0ET::CIWj4x1HTi callvirt System.Void rd1R1vPegCl1wu10V1g.snOQKDPYTkcX9ChY08T::DebYB92x5X() nop <null> ret <null>

hyperbroker.exe (1.23 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙