Suspicious
Suspect

e94c6359a5f2959eb9beb546f1774f06

PE Executable
MD5: e94c6359a5f2959eb9beb546f1774f06
Size: 2.68 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 e94c6359a5f2959eb9beb546f1774f06
Sha1 ef380492e2e43f3f6ddf42d285ac9ebb108e1c1c
Sha256 da0cb3ce20b18d06d4bb6101c124b366dde585db8ce21ec42b413ca9d0d1b5e9
Sha384 59b185fbc30efc8a44b4cb3a7172073ec6698c496eed682e9de3efdc33feb7304243d0bb62d96bb32fcecb1e05c58888
Sha512 330c33324992e0f96651e758359a839c53c1cc39c90407ac2e790530f4447463f99d3f74b6e25ffb198b46bca00b8fc405201ab7f34f91ede857a743a09f3d27
SSDeep 49152:EaOUS6Hp8mnBJ3Tpc8iYMC1yx5f6yflFkBHT9P+X5+NGuxCGggyM3el:DOf6p8mBZTFMCUxQyfUB45+lxAg
TLSH C6C512837C8B1F3EC4590931CAB53F2322EC6B51BA615DD3EBB9119E6E651C0D2D42E2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EpQGQFGmaDaw.ObCDsET1.dut
1LyT2OZ.bat
7z-stream @ 0x000C6D78.7z
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.sxdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
.rsrc
Resources
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
Resources
RT_CURSOR
ID:0001
ID:1033
RT_DIALOG
ID:0066
ID:1037
ID:0070
ID:1037
RT_GROUP_CURSOR2
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1037
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
STRING
ID:07D1
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
ID:07D2
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
ID:07D3
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0-preview.png
RT_DIALOG
ID:0069
ID:0
ID:0084
ID:0
RT_GROUP_CURSOR4
ID:07D0
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.didat
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_MANIFEST
ID:0001
ID:1033
         
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
DownloaderApp.exe
Full Name
DownloaderApp.exe
EntryPoint
System.Void  ::(System.String[])
Scope Name
DownloaderApp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DownloaderApp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
0
Main Method
System.Void  ::(System.String[])
Main IL Instruction Count
106
Main IL
call System.Boolean  ::()
brtrue.s IL_0015: call System.Boolean System.Environment::get_UserInteractive()
call System.Void  ::()
leave.s IL_0014: ret
pop <null>
leave IL_0155: ret
ret <null>
call System.Boolean System.Environment::get_UserInteractive()
brtrue.s IL_0027: ldc.i4 634257481
newobj System.Void  ::.ctor()
call System.Void System.ServiceProcess.ServiceBase::Run(System.ServiceProcess.ServiceBase)
ret <null>
ldc.i4 634257481
call System.String  ::(System.Int32)
stloc.2 <null>
ldc.i4 634257494
call System.String  ::(System.Int32)
stloc.3 <null>
ldc.i4 634257535
call System.String  ::(System.Int32)
stloc.s V_4
ldc.i4.s 36
call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder)
dup <null>
ldloc.2 <null>
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.0 <null>
ldloc.3 <null>
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.1 <null>
ldc.i4 634257415
call System.String  ::(System.Int32)
ldloc.0 <null>
call System.Void  ::(System.String,System.String)
ldc.i4 634257447
call System.String  ::(System.Int32)
ldloc.1 <null>
call System.Void  ::(System.String,System.String)
ldloc.0 <null>
ldc.i4.6 <null>
call System.Void System.IO.File::SetAttributes(System.String,System.IO.FileAttributes)
ldloc.1 <null>
ldc.i4.6 <null>
call System.Void System.IO.File::SetAttributes(System.String,System.IO.FileAttributes)
ldloc.0 <null>
call System.Void  ::(System.String)
ldloc.1 <null>
call System.Void  ::(System.String)
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
callvirt System.String System.Reflection.Assembly::get_Location()
call System.Void  ::(System.String)
ldloc.0 <null>
ldloc.s V_4
call System.Void  ::(System.String,System.String)
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
dup <null>
ldc.i4 634257607
call System.String  ::(System.Int32)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String)
dup <null>
ldc.i4 634257621
call System.String  ::(System.Int32)
ldloc.0 <null>
ldc.i4 634257633
call System.String  ::(System.Int32)
call System.String System.String::Concat(System.String,System.String,System.String)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Arguments(System.String)
dup <null>
ldc.i4.0 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WindowStyle(System.Diagnostics.ProcessWindowStyle)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo)
pop <null>
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
dup <null>
ldc.i4 634257607
call System.String  ::(System.Int32)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String)
dup <null>
ldc.i4 634257621
call System.String  ::(System.Int32)
ldloc.1 <null>
ldc.i4 634257633
call System.String  ::(System.Int32)
call System.String System.String::Concat(System.String,System.String,System.String)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Arguments(System.String)
dup <null>
ldc.i4.0 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WindowStyle(System.Diagnostics.ProcessWindowStyle)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo)
pop <null>
leave.s IL_0155: ret
pop <null>
leave.s IL_0155: ret
ret <null>
Module Name
DownloaderApp.exe
Full Name
DownloaderApp.exe
EntryPoint
System.Void  ::(System.String[])
Scope Name
DownloaderApp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DownloaderApp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
0
Main Method
System.Void  ::(System.String[])
Main IL Instruction Count
106
Main IL
call System.Boolean  ::()
brtrue.s IL_0015: call System.Boolean System.Environment::get_UserInteractive()
call System.Void  ::()
leave.s IL_0014: ret
pop <null>
leave IL_0155: ret
ret <null>
call System.Boolean System.Environment::get_UserInteractive()
brtrue.s IL_0027: ldc.i4 634257481
newobj System.Void  ::.ctor()
call System.Void System.ServiceProcess.ServiceBase::Run(System.ServiceProcess.ServiceBase)
ret <null>
ldc.i4 634257481
call System.String  ::(System.Int32)
stloc.2 <null>
ldc.i4 634257494
call System.String  ::(System.Int32)
stloc.3 <null>
ldc.i4 634257535
call System.String  ::(System.Int32)
stloc.s V_4
ldc.i4.s 36
call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder)
dup <null>
ldloc.2 <null>
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.0 <null>
ldloc.3 <null>
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.1 <null>
ldc.i4 634257415
call System.String  ::(System.Int32)
ldloc.0 <null>
call System.Void  ::(System.String,System.String)
ldc.i4 634257447
call System.String  ::(System.Int32)
ldloc.1 <null>
call System.Void  ::(System.String,System.String)
ldloc.0 <null>
ldc.i4.6 <null>
call System.Void System.IO.File::SetAttributes(System.String,System.IO.FileAttributes)
ldloc.1 <null>
ldc.i4.6 <null>
call System.Void System.IO.File::SetAttributes(System.String,System.IO.FileAttributes)
ldloc.0 <null>
call System.Void  ::(System.String)
ldloc.1 <null>
call System.Void  ::(System.String)
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
callvirt System.String System.Reflection.Assembly::get_Location()
call System.Void  ::(System.String)
ldloc.0 <null>
ldloc.s V_4
call System.Void  ::(System.String,System.String)
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
dup <null>
ldc.i4 634257607
call System.String  ::(System.Int32)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String)
dup <null>
ldc.i4 634257621
call System.String  ::(System.Int32)
ldloc.0 <null>
ldc.i4 634257633
call System.String  ::(System.Int32)
call System.String System.String::Concat(System.String,System.String,System.String)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Arguments(System.String)
dup <null>
ldc.i4.0 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WindowStyle(System.Diagnostics.ProcessWindowStyle)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo)
pop <null>
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
dup <null>
ldc.i4 634257607
call System.String  ::(System.Int32)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String)
dup <null>
ldc.i4 634257621
call System.String  ::(System.Int32)
ldloc.1 <null>
ldc.i4 634257633
call System.String  ::(System.Int32)
call System.String System.String::Concat(System.String,System.String,System.String)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Arguments(System.String)
dup <null>
ldc.i4.0 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WindowStyle(System.Diagnostics.ProcessWindowStyle)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo)
pop <null>
leave.s IL_0155: ret
pop <null>
leave.s IL_0155: ret
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
EpQGQFGmaDaw.ObCDsET1.dut
1LyT2OZ.bat
7z-stream @ 0x000C6D78.7z
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.sxdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
UPX0
UPX1
.rsrc
Resources
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
Resources
RT_CURSOR
ID:0001
ID:1033
RT_DIALOG
ID:0066
ID:1037
ID:0070
ID:1037
RT_GROUP_CURSOR2
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1037
RT_MANIFEST
ID:0001
ID:1033
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
STRING
ID:07D1
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
ID:07D2
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
ID:07D3
ID:4
ID:7
ID:9
ID:10
ID:12
ID:1028
ID:1040
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0-preview.png
RT_DIALOG
ID:0069
ID:0
ID:0084
ID:0
RT_GROUP_CURSOR4
ID:07D0
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.didat
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_MANIFEST
ID:0001
ID:1033
         
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙