Suspicious
Suspect

d7911307943abbf4750b1c5040642d4e

PE Executable
|
MD5: d7911307943abbf4750b1c5040642d4e
|
Size: 1.14 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
d7911307943abbf4750b1c5040642d4e
Sha1
1702cf1a2a5fe9a3f3a1d87960abdc698c1aa0c8
Sha256
8a0a1c0a305381c48d65ab4be874a4651c4446bc6067b6592db673c5664658de
Sha384
5aa9866c897c0f1e017fae8ebf57a6af426f6df56827fbb157f12a6d073d909e5391209a06b93952aed67cc196f61894
Sha512
2da0fd844ac88bf53f6f5089b7f51a004d58ca242f2b819d77b6088560f7e8fb55671d3d672edf10a0209d5e50ae93035c845911a77c26e86e7c57e185702c95
SSDeep
24576:lifZNC8ZHKJCX0fI8mVS7dXng07ehJKYC:WZWWgI8mchgGehp
TLSH
AE35E00723D44A68E5BD9B7A85BA14D103FFBB47AB32DB0C6C0951EB0D26B41DE41B63

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
BargainingPlat.temona.json
Mcb5nK.Resources.resources
fdf1df58419e61.Resources.resources
d370c16a0
[NBF]root.Data
d370c16a1
[NBF]root.Data
d370c16a10
[NBF]root.Data
d370c16a11
[NBF]root.Data
d370c16a12
[NBF]root.Data
d370c16a13
[NBF]root.Data
d370c16a14
[NBF]root.Data
d370c16a15
[NBF]root.Data
d370c16a16
[NBF]root.Data
d370c16a17
[NBF]root.Data
d370c16a18
[NBF]root.Data
d370c16a19
[NBF]root.Data
d370c16a2
[NBF]root.Data
d370c16a20
[NBF]root.Data
d370c16a21
[NBF]root.Data
d370c16a22
[NBF]root.Data
d370c16a23
[NBF]root.Data
d370c16a24
[NBF]root.Data
d370c16a3
[NBF]root.Data
d370c16a4
[NBF]root.Data
d370c16a5
[NBF]root.Data
d370c16a6
[NBF]root.Data
d370c16a7
[NBF]root.Data
d370c16a8
[NBF]root.Data
d370c16a9
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Mcb5nK

Full Name

Mcb5nK

EntryPoint

System.Void Mcb5nK.qAa1N6pk8j::yo2F1KcgSx9mnY()

Scope Name

Mcb5nK

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Mcb5nK

Assembly Version

29.27.15.65

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

815

Main Method

System.Void Mcb5nK.qAa1N6pk8j::yo2F1KcgSx9mnY()

Main IL Instruction Count

121

Main IL

nop <null> nop <null> ldstr EU-EN1749 stloc.0 <null> ldc.i4 30000 stloc.1 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.2 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Collections.Generic.Dictionary`2<System.String,System.Object>::.ctor() stloc.s V_12 ldloc.s V_12 ldstr Floors ldc.i4.s 12 box System.Int32 callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.Object>::Add(System.String,System.Object) nop <null> ldloc.s V_12 ldstr YearBuilt ldc.i4 2018 box System.Int32 callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.Object>::Add(System.String,System.Object) nop <null> ldloc.s V_12 ldstr EnergyRating ldstr B+ callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.Object>::Add(System.String,System.Object) nop <null> ldloc.s V_12 stloc.3 <null> ldc.i4.s 20 stloc.s V_4 newobj System.Void System.Collections.Generic.List`1<System.Int32>::.ctor() stloc.s V_5 ldloc.s V_4 stloc.s V_13 ldc.i4.1 <null> stloc.s V_14 br.s IL_0085: ldloc.s V_14 ldloc.s V_5 ldloc.s V_14 callvirt System.Void System.Collections.Generic.List`1<System.Int32>::Add(System.Int32) nop <null> ldloc.s V_14 ldc.i4.1 <null> add.ovf <null> stloc.s V_14 ldloc.s V_14 ldloc.s V_13 ble.s IL_0075: ldloc.s V_5 ldstr FacilityOptima.Core stloc.s V_6 ldstr 2.4.1 stloc.s V_7 call System.Guid System.Guid::NewGuid() stloc.s V_15 ldloca.s V_15 ldstr N call System.String System.Guid::ToString(System.String) ldc.i4.0 <null> ldc.i4.s 12 callvirt System.String System.String::Substring(System.Int32,System.Int32) stloc.s V_8 ldloc.s V_5 callvirt System.Int32 System.Collections.Generic.List`1<System.Int32>::get_Count() ldloc.s V_4 ceq <null> ldc.i4.0 <null> ceq <null> stloc.s V_16 ldloc.s V_16 brfalse.s IL_00D2: nop ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> nop <null> nop <null> ldc.i4.1 <null> stloc.s V_9 ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr FacilityOptima ldstr Cache call System.String System.IO.Path::Combine(System.String,System.String,System.String) stloc.s V_10 ldloc.s V_10 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_17 ldloc.s V_17 brfalse.s IL_0107: nop ldloc.s V_10 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> nop <null> nop <null> call System.Int32 System.Environment::get_TickCount() conv.i8 <null> stloc.s V_11 ldc.i4.s 40 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldstr temona.json call System.Void Mcb5nK.9Jgqo/Wa5is6.7WayXrs8::Hyn30cKijJ9(System.String) nop <null> call System.Void System.GC::Collect() nop <null> call System.Void System.GC::WaitForPendingFinalizers() nop <null> leave.s IL_0145: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0145: nop nop <null> ret <null>

Module Name

Mcb5nK

Full Name

Mcb5nK

EntryPoint

System.Void Mcb5nK.qAa1N6pk8j::yo2F1KcgSx9mnY()

Scope Name

Mcb5nK

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Mcb5nK

Assembly Version

29.27.15.65

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

815

Main Method

System.Void Mcb5nK.qAa1N6pk8j::yo2F1KcgSx9mnY()

Main IL Instruction Count

121

Main IL

nop <null> nop <null> ldstr EU-EN1749 stloc.0 <null> ldc.i4 30000 stloc.1 <null> newobj System.Void System.Windows.Forms.Form::.ctor() stloc.2 <null> call System.Void System.Windows.Forms.Application::EnableVisualStyles() nop <null> newobj System.Void System.Collections.Generic.Dictionary`2<System.String,System.Object>::.ctor() stloc.s V_12 ldloc.s V_12 ldstr Floors ldc.i4.s 12 box System.Int32 callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.Object>::Add(System.String,System.Object) nop <null> ldloc.s V_12 ldstr YearBuilt ldc.i4 2018 box System.Int32 callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.Object>::Add(System.String,System.Object) nop <null> ldloc.s V_12 ldstr EnergyRating ldstr B+ callvirt System.Void System.Collections.Generic.Dictionary`2<System.String,System.Object>::Add(System.String,System.Object) nop <null> ldloc.s V_12 stloc.3 <null> ldc.i4.s 20 stloc.s V_4 newobj System.Void System.Collections.Generic.List`1<System.Int32>::.ctor() stloc.s V_5 ldloc.s V_4 stloc.s V_13 ldc.i4.1 <null> stloc.s V_14 br.s IL_0085: ldloc.s V_14 ldloc.s V_5 ldloc.s V_14 callvirt System.Void System.Collections.Generic.List`1<System.Int32>::Add(System.Int32) nop <null> ldloc.s V_14 ldc.i4.1 <null> add.ovf <null> stloc.s V_14 ldloc.s V_14 ldloc.s V_13 ble.s IL_0075: ldloc.s V_5 ldstr FacilityOptima.Core stloc.s V_6 ldstr 2.4.1 stloc.s V_7 call System.Guid System.Guid::NewGuid() stloc.s V_15 ldloca.s V_15 ldstr N call System.String System.Guid::ToString(System.String) ldc.i4.0 <null> ldc.i4.s 12 callvirt System.String System.String::Substring(System.Int32,System.Int32) stloc.s V_8 ldloc.s V_5 callvirt System.Int32 System.Collections.Generic.List`1<System.Int32>::get_Count() ldloc.s V_4 ceq <null> ldc.i4.0 <null> ceq <null> stloc.s V_16 ldloc.s V_16 brfalse.s IL_00D2: nop ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> nop <null> nop <null> ldc.i4.1 <null> stloc.s V_9 ldc.i4.s 28 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) ldstr FacilityOptima ldstr Cache call System.String System.IO.Path::Combine(System.String,System.String,System.String) stloc.s V_10 ldloc.s V_10 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_17 ldloc.s V_17 brfalse.s IL_0107: nop ldloc.s V_10 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> nop <null> nop <null> call System.Int32 System.Environment::get_TickCount() conv.i8 <null> stloc.s V_11 ldc.i4.s 40 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldstr temona.json call System.Void Mcb5nK.9Jgqo/Wa5is6.7WayXrs8::Hyn30cKijJ9(System.String) nop <null> call System.Void System.GC::Collect() nop <null> call System.Void System.GC::WaitForPendingFinalizers() nop <null> leave.s IL_0145: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0145: nop nop <null> ret <null>

d7911307943abbf4750b1c5040642d4e (1.14 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
BargainingPlat.temona.json
Mcb5nK.Resources.resources
fdf1df58419e61.Resources.resources
d370c16a0
[NBF]root.Data
d370c16a1
[NBF]root.Data
d370c16a10
[NBF]root.Data
d370c16a11
[NBF]root.Data
d370c16a12
[NBF]root.Data
d370c16a13
[NBF]root.Data
d370c16a14
[NBF]root.Data
d370c16a15
[NBF]root.Data
d370c16a16
[NBF]root.Data
d370c16a17
[NBF]root.Data
d370c16a18
[NBF]root.Data
d370c16a19
[NBF]root.Data
d370c16a2
[NBF]root.Data
d370c16a20
[NBF]root.Data
d370c16a21
[NBF]root.Data
d370c16a22
[NBF]root.Data
d370c16a23
[NBF]root.Data
d370c16a24
[NBF]root.Data
d370c16a3
[NBF]root.Data
d370c16a4
[NBF]root.Data
d370c16a5
[NBF]root.Data
d370c16a6
[NBF]root.Data
d370c16a7
[NBF]root.Data
d370c16a8
[NBF]root.Data
d370c16a9
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙