Suspicious
Suspect

de9fe81dd0a1a61b02dbc84cd5479535

PE Executable
|
MD5: de9fe81dd0a1a61b02dbc84cd5479535
|
Size: 1.72 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Medium

Hash
Hash Value
MD5
de9fe81dd0a1a61b02dbc84cd5479535
Sha1
916544a5d4c48b2a36da93c6c7a13ee582e33e6b
Sha256
94d3ea79f8c5ca711431010276ec84db1eab20e8d33f2c2293e8f3347d378adf
Sha384
3165235954dfab15b5ffac5b2216526cc3edaee432c5f3429071440d4c0e3d658b63cbe1d119a8a419f2657853418bea
Sha512
acfed19dbdf2e1b3a032f78e5add768043d34a1fbe51dfbacabbedf5982c401a435239046f79a107ba7e455b4e43ba6082a0899cec692f78dde00bd123d2a104
SSDeep
49152:0rhGflnXlXnm3pyw1XfUXngXjAGslTF2euhA:0r2nXZqp5f0Pueu
TLSH
BA85230BF94FC2B0C2909BBAC4EA869503B9C740E657DC5B79FA278E16137FD8940587

PeID

Microsoft Visual C++ DLL
Microsoft Visual C++ v6.0
Microsoft Visual C++ v6.0 DLL
File Structure
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Ghwvvdxhqpk.Properties.Resources.resources
Yfseychtsgv
TimeZoneConverter.Data.Aliases.csv.gz
file_0.bin
TimeZoneConverter.Data.Mapping.csv.gz
file_0.bin
TimeZoneConverter.Data.RailsMapping.csv.gz
file_0.bin
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

newAI_crypted.exe

Full Name

newAI_crypted.exe

EntryPoint

System.Void newAI_crypted.Networking.SorterModule::CloseGeneralConnection()

Scope Name

newAI_crypted.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

newAI_crypted

Assembly Version

1.0.4634.4486

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

82

Main Method

System.Void newAI_crypted.Networking.SorterModule::CloseGeneralConnection()

Main IL Instruction Count

137

Main IL

ldc.i4 7 stloc V_8 br IL_000E: ldloc V_8 ldloc V_8 switch dnlib.DotNet.Emit.Instruction[] br IL_0040: newobj System.Void newAI_crypted.Verification.VerifierAnalyzer::.ctor() newobj System.Void newAI_crypted.Verification.VerifierAnalyzer::.ctor() stloc.s V_2 ldc.i4 5 br IL_0012: switch(IL_0040,IL_01CD,IL_01CE,IL_01B6,IL_01F7,IL_0232,IL_0243,IL_021D,IL_0051) nop <null> nop <null> ldloc.s V_7 ldloc.s V_6 ldftn System.Void Ghwvvdxhqpk.Drivers.DriverAllocator::ForceTransformableDriver(System.Object,Ghwvvdxhqpk.Location.IterableLocator) newobj System.Void System.EventHandler`1<Ghwvvdxhqpk.Location.IterableLocator>::.ctor(System.Object,System.IntPtr) callvirt System.Void newAI_crypted.Roles.RoleCompressor::EvaluateRole(System.EventHandler`1<Ghwvvdxhqpk.Location.IterableLocator>) ldc.i4 2 br IL_0075: switch(IL_0093,IL_00D9,IL_00F8,IL_012C,IL_00A5) ldloc V_1 switch dnlib.DotNet.Emit.Instruction[] br IL_0093: nop nop <null> ldloc.s V_7 callvirt System.Void newAI_crypted.Roles.RoleCompressor::QueryRole() ldc.i4 3 br IL_0075: switch(IL_0093,IL_00D9,IL_00F8,IL_012C,IL_00A5) nop <null> ldloc.s V_4 ldloc.s V_6 ldftn System.Void Ghwvvdxhqpk.Drivers.DriverAllocator::AttachDriver(System.Object,newAI_crypted.Finalization.FinalizerBridge) newobj System.Void System.EventHandler`1<newAI_crypted.Finalization.FinalizerBridge>::.ctor(System.Object,System.IntPtr) callvirt System.Void newAI_crypted.Roles.StaticRole::ChangeRole(System.EventHandler`1<newAI_crypted.Finalization.FinalizerBridge>) ldc.i4 0 ldsfld <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63} <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_7083c69c7f2e40259314cb294c2cec7f ldfld System.Int32 <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_76a5d2fd39684637929e9b0feecbb35b brtrue IL_0075: switch(IL_0093,IL_00D9,IL_00F8,IL_012C,IL_00A5) pop <null> ldc.i4 0 br IL_0075: switch(IL_0093,IL_00D9,IL_00F8,IL_012C,IL_00A5) nop <null> ldloc.s V_3 ldloc.s V_6 ldftn System.Void Ghwvvdxhqpk.Drivers.DriverAllocator::RunTransferableDriver(System.Object,Ghwvvdxhqpk.Compilers.GlobalCompiler) newobj System.Void System.EventHandler`1<Ghwvvdxhqpk.Compilers.GlobalCompiler>::.ctor(System.Object,System.IntPtr) callvirt System.Void newAI_crypted.Visitors.DynamicVisitor::VisitIntegratedVisitor(System.EventHandler`1<Ghwvvdxhqpk.Compilers.GlobalCompiler>) ldc.i4 4 br IL_0075: switch(IL_0093,IL_00D9,IL_00F8,IL_012C,IL_00A5) nop <null> ldloc.s V_2 ldloc.s V_6 ldftn System.Void Ghwvvdxhqpk.Drivers.DriverAllocator::FormatDriver(System.Object,newAI_crypted.Visitors.ConnectedVisitor) newobj System.Void System.EventHandler`1<newAI_crypted.Visitors.ConnectedVisitor>::.ctor(System.Object,System.IntPtr) callvirt System.Void newAI_crypted.Verification.VerifierAnalyzer::ValidateCustomVerifier(System.EventHandler`1<newAI_crypted.Visitors.ConnectedVisitor>) ldc.i4 1 ldsfld <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63} <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_7083c69c7f2e40259314cb294c2cec7f ldfld System.Int32 <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_b17435f6a52542a298b404ca69b102ed brtrue IL_0075: switch(IL_0093,IL_00D9,IL_00F8,IL_012C,IL_00A5) pop <null> ldc.i4 0 br IL_0075: switch(IL_0093,IL_00D9,IL_00F8,IL_012C,IL_00A5) nop <null> nop <null> leave IL_01CD: ret ldloc.s V_6 brfalse IL_0196: endfinally ldc.i4 0 ldsfld <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63} <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_7083c69c7f2e40259314cb294c2cec7f ldfld System.Int32 <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_00e73bf1bf2d4b708095f9ef286ae1c4 brfalse IL_015D: switch(IL_0195,IL_016F) pop <null> ldc.i4 1 br IL_015D: switch(IL_0195,IL_016F) ldloc V_5 switch dnlib.DotNet.Emit.Instruction[] br IL_0195: nop ldloc.s V_6 callvirt System.Void System.IDisposable::Dispose() ldc.i4 0 ldsfld <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63} <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_7083c69c7f2e40259314cb294c2cec7f ldfld System.Int32 <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_76a5d2fd39684637929e9b0feecbb35b brtrue IL_015D: switch(IL_0195,IL_016F) pop <null> ldc.i4 0 br IL_015D: switch(IL_0195,IL_016F) nop <null> endfinally <null> ldc.i4 1 ldsfld <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63} <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_7083c69c7f2e40259314cb294c2cec7f ldfld System.Int32 <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_3cab821d6b044a098e162a5b80b10fa2 brtrue IL_0012: switch(IL_0040,IL_01CD,IL_01CE,IL_01B6,IL_01F7,IL_0232,IL_0243,IL_021D,IL_0051) pop <null> ldc.i4 1 br IL_0012: switch(IL_0040,IL_01CD,IL_01CE,IL_01B6,IL_01F7,IL_0232,IL_0243,IL_021D,IL_0051) ldloc.s V_2 ldloc.s V_3 ldloc.s V_4 newobj System.Void Ghwvvdxhqpk.Drivers.DriverAllocator::.ctor(newAI_crypted.Verification.VerifierAnalyzer,newAI_crypted.Visitors.DynamicVisitor,newAI_crypted.Roles.StaticRole) stloc.s V_6 ldc.i4 8 br IL_0012: switch(IL_0040,IL_01CD,IL_01CE,IL_01B6,IL_01F7,IL_0232,IL_0243,IL_021D,IL_0051) ret <null> ldnull <null> ldloc.s V_0 newobj System.Void newAI_crypted.Roles.RoleCompressor::.ctor(System.String,System.Version) stloc.s V_7 ldc.i4 0 ldsfld <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63} <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_7083c69c7f2e40259314cb294c2cec7f ldfld System.Int32 <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_28a9c2d10286444ebfb31d867c06cbfb brtrue IL_0012: switch(IL_0040,IL_01CD,IL_01CE,IL_01B6,IL_01F7,IL_0232,IL_0243,IL_021D,IL_0051) pop <null> ldc.i4 0 br IL_0012: switch(IL_0040,IL_01CD,IL_01CE,IL_01B6,IL_01F7,IL_0232,IL_0243,IL_021D,IL_0051) newobj System.Void newAI_crypted.Roles.StaticRole::.ctor() stloc.s V_4 ldc.i4 0 ldsfld <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63} <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_7083c69c7f2e40259314cb294c2cec7f ldfld System.Int32 <Module>{e609ab33-60e2-4c76-ae15-6cf27a52bf63}::m_453d130c975c441f8bb0ba4c8192270d brtrue IL_0012: switch(IL_0040,IL_01CD,IL_01CE,IL_01B6,IL_01F7,IL_0232,IL_0243,IL_021D,IL_0051) pop <null> ldc.i4 3 br IL_0012: switch(IL_0040,IL_01CD,IL_01CE,IL_01B6,IL_01F7,IL_0232,IL_0243,IL_021D,IL_0051) nop <null> ldc.i4 4032 call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType) ldc.i4 6 br IL_0012: switch(IL_0040,IL_01CD,IL_01CE,IL_01B6,IL_01F7,IL_0232,IL_0243,IL_021D,IL_0051) newobj System.Void newAI_crypted.Visitors.DynamicVisitor::.ctor() stloc.s V_3 ldc.i4 4 br IL_0012: switch(IL_0040,IL_01CD,IL_01CE,IL_01B6,IL_01F7,IL_0232,IL_0243,IL_021D,IL_0051) nop <null> ldstr 1.4.1 newobj System.Void System.Version::.ctor(System.String) stloc.s V_0 ldc.i4 2 br IL_0012: switch(IL_0040,IL_01CD,IL_01CE,IL_01B6,IL_01F7,IL_0232,IL_0243,IL_021D,IL_0051)

de9fe81dd0a1a61b02dbc84cd5479535 (1.72 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙