Malicious
Malicious

ed4177c0fbb0df70feb83d4f13358dbb

PE Executable
|
MD5: ed4177c0fbb0df70feb83d4f13358dbb
|
Size: 1.93 MB
|
application/x-dosexec


Print
Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Very high

Hash
Hash Value
MD5
ed4177c0fbb0df70feb83d4f13358dbb
Sha1
55951e4df0cb7c2a43d320c785d3a5e117b78816
Sha256
a24669b3718039277024a4ec115f4039a7ecf4469485b169dd35f288c232ef24
Sha384
2015ef430881b33391d9df3143418ebe883bbdb81eca76fff6f25dc32f52c1cad324f84518c8e9cb115999fbd69b73e6
Sha512
9727efaf16d2d3a236ddd9e16436d18a455b43f6c33ca5fe6f65dfa0aa3800e82df87c6595b10d92e603450239ff4e7f8c15188222cf01ef744f0a14cf7e0364
SSDeep
24576:zL9RpHiLemUkXi2bwRCe0VjyjmtYkJ8tfJf8FlzCr6rhQZC/4hVHHEZ6CEC43rNs:HRie5GY3PVHkZ6Cp47NZmNkd
TLSH
2A95BF0676924E37C2605B318A97113D92E2CBA63512EF1F351F25E2A91F7F18A721F3

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
A968owlsy6kG5vo7Mg.OWPHZlnhvMhBSCYf17
TOl9Jv9kkyL4BFiEdE.RAGRvKf9EAnMy2fw7n
R1nXmOYrLZ2cJrYK1U.34gbMUMysp9WPAW0N5
1nYAReiJZ7OYgiW2h6.woh6uYraYlpOW7HROO
d5FB0CeDr5xYb6jWMg.eF5wDxPPrJTA3eTvvV
r1BDrL4JMV4aZf11wP.5DEJZoKmOEU9bY63wO
Informations
Name
Value
Module Name

pxqDsBPmp0nY

Full Name

pxqDsBPmp0nY

EntryPoint

System.Void M3diwvjPliEJHNRQ1vj.PEenFlje5HYlf7xyF6X::gy1jlZk8tI()

Scope Name

pxqDsBPmp0nY

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

SGxDUr5uRrbW2X9YcTIdUkMi5E

Assembly Version

4.1.5.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

47

Main Method

System.Void M3diwvjPliEJHNRQ1vj.PEenFlje5HYlf7xyF6X::gy1jlZk8tI()

Main IL Instruction Count

41

Main IL

ldc.i4 3 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_00AE: ret call System.Void TiJWHnhmDhZnSNGp55H.Sae7fYhWq16i4MffL2x::Xt4Kn3lKB5t() ldc.i4 2 br IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F) ldnull <null> ldnull <null> newobj System.Void nf3YaPPHyENRIDyOUEU.nNk0sCPw2HwGoOboMjq::.ctor(System.String,System.String) call System.Void vHZB8fKcA81pu78s1wb.Hin6vYKjjyAKMfXw46S::FutKbyloCx(nf3YaPPHyENRIDyOUEU.nNk0sCPw2HwGoOboMjq) ldc.i4 0 ldsfld <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc} <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_2862b1ac51e3463b9d5f6a8fe957515c ldfld System.Int32 <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_584072bebe3f43c0a3c6de47aff9c608 brfalse IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F) pop <null> ldc.i4 1 br IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F) ldc.i4 -1127243949 ldc.i4 -310370757 xor <null> ldsfld <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc} <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_2862b1ac51e3463b9d5f6a8fe957515c ldfld System.Int32 <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_c27c294b3e954ea5b297a55e41f7ac80 xor <null> call System.String u1ndWjSWyLyDNR89Ijx.vUh3YVSxQU3xGdGYged::ueRSBDjTtl(System.Int32) newobj System.Void xwgGbhM92XKk7EbEwFB.AJ6XR2MrgdU50yBdWUJ::.ctor(System.String) call System.Void xwgGbhM92XKk7EbEwFB.AJ6XR2MrgdU50yBdWUJ::OPsMfnVOVn() ldc.i4 0 ldsfld <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc} <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_2862b1ac51e3463b9d5f6a8fe957515c ldfld System.Int32 <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_8cfe5355ad8c41c993e6ded785e234bc brtrue IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F) pop <null> ldc.i4 0 br IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F) ret <null> newobj System.Void TuNuUEYrdo8yYHfTcOb.H0Ob7qYiGjLN1bCswu6::.ctor() pop <null> ldc.i4 4 br IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F)

Module Name

pxqDsBPmp0nY

Full Name

pxqDsBPmp0nY

EntryPoint

System.Void M3diwvjPliEJHNRQ1vj.PEenFlje5HYlf7xyF6X::gy1jlZk8tI()

Scope Name

pxqDsBPmp0nY

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

SGxDUr5uRrbW2X9YcTIdUkMi5E

Assembly Version

4.1.5.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

47

Main Method

System.Void M3diwvjPliEJHNRQ1vj.PEenFlje5HYlf7xyF6X::gy1jlZk8tI()

Main IL Instruction Count

41

Main IL

ldc.i4 3 stloc V_0 br IL_000E: ldloc V_0 ldloc V_0 switch dnlib.DotNet.Emit.Instruction[] br IL_00AE: ret call System.Void TiJWHnhmDhZnSNGp55H.Sae7fYhWq16i4MffL2x::Xt4Kn3lKB5t() ldc.i4 2 br IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F) ldnull <null> ldnull <null> newobj System.Void nf3YaPPHyENRIDyOUEU.nNk0sCPw2HwGoOboMjq::.ctor(System.String,System.String) call System.Void vHZB8fKcA81pu78s1wb.Hin6vYKjjyAKMfXw46S::FutKbyloCx(nf3YaPPHyENRIDyOUEU.nNk0sCPw2HwGoOboMjq) ldc.i4 0 ldsfld <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc} <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_2862b1ac51e3463b9d5f6a8fe957515c ldfld System.Int32 <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_584072bebe3f43c0a3c6de47aff9c608 brfalse IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F) pop <null> ldc.i4 1 br IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F) ldc.i4 -1127243949 ldc.i4 -310370757 xor <null> ldsfld <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc} <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_2862b1ac51e3463b9d5f6a8fe957515c ldfld System.Int32 <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_c27c294b3e954ea5b297a55e41f7ac80 xor <null> call System.String u1ndWjSWyLyDNR89Ijx.vUh3YVSxQU3xGdGYged::ueRSBDjTtl(System.Int32) newobj System.Void xwgGbhM92XKk7EbEwFB.AJ6XR2MrgdU50yBdWUJ::.ctor(System.String) call System.Void xwgGbhM92XKk7EbEwFB.AJ6XR2MrgdU50yBdWUJ::OPsMfnVOVn() ldc.i4 0 ldsfld <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc} <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_2862b1ac51e3463b9d5f6a8fe957515c ldfld System.Int32 <Module>{fd0d7790-ed00-4a2f-95e3-5089afa2c1cc}::m_8cfe5355ad8c41c993e6ded785e234bc brtrue IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F) pop <null> ldc.i4 0 br IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F) ret <null> newobj System.Void TuNuUEYrdo8yYHfTcOb.H0Ob7qYiGjLN1bCswu6::.ctor() pop <null> ldc.i4 4 br IL_0012: switch(IL_00AE,IL_006A,IL_00AF,IL_0030,IL_003F)

ed4177c0fbb0df70feb83d4f13358dbb (1.93 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙