Suspicious
Suspect

PE Executable
MD5: f6b62e6d68452a089027895eb53fc0ce
Size: 1.09 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 f6b62e6d68452a089027895eb53fc0ce
Sha1 decfdace15341fdf0a054b9773296915db084088
Sha256 83e2da5c31bfc959a3c8933425033efd0ffa10de87dbff72be9da672f3ad8d41
Sha384 c2cd08aa7748db41a958820ef1cc70c45bce5755b266cf219be1e416bee64f07e4f69128d83430c7877a0379db4c0c68
Sha512 36c3ef7a2b24ff7319ee4c259d8bf9ff47c777e6faa545ef74253a3de104a2867735288819b3cf7dc8e659ee1cb3825a75f46c7e89581b77e53cd82a6e06a3d0
SSDeep 24576:Ud4oouMQDcO3yd15Fsd4Vwols8LT7WX+3oPAs1Ys8J:UfVpDBCd1Y4VEST9mtOs
TLSH 62353398E3E09B26D277067978620B0041D4B503C613B32FEF4925C5FED2ADD45FA66B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Cbwsasck.Properties.Resources.resources
Oztdsma
ILRepack.List
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Unvewsmnma
Full Name
Unvewsmnma
EntryPoint
System.Void Cbwsasck.Yxbkov::Main()
Scope Name
Unvewsmnma
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Unvewsmnma
Assembly Version
1.0.7447.5481
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
48
Main Method
System.Void Cbwsasck.Yxbkov::Main()
Main IL Instruction Count
60
Main IL
newobj System.Void Cbwsasck.Yxbkov/<>c__DisplayClass0_0::.ctor()
stloc.0 <null>
ldstr 4H+11ueoUjTdoP4vTzcLzw==
stloc.1 <null>
ldstr VZhmP0Bn1Ok=
stloc.2 <null>
ldsfld System.Func`1<System.Byte[]> Cbwsasck.Yxbkov/<>c::<>9__0_0
dup <null>
brtrue.s IL_0031: newobj System.Void Cbwsasck.Xiwycrb::.ctor(System.Func`1<System.Byte[]>)
pop <null>
ldsfld Cbwsasck.Yxbkov/<>c Cbwsasck.Yxbkov/<>c::<>9
ldftn System.Byte[] Cbwsasck.Yxbkov/<>c::<Main>b__0_0()
newobj System.Void System.Func`1<System.Byte[]>::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.Func`1<System.Byte[]> Cbwsasck.Yxbkov/<>c::<>9__0_0
newobj System.Void Cbwsasck.Xiwycrb::.ctor(System.Func`1<System.Byte[]>)
ldloc.0 <null>
ldloc.1 <null>
ldloc.2 <null>
newobj System.Void Cbwsasck.Nrlycngwss::.ctor(System.String,System.String)
stfld Cbwsasck.Nrlycngwss Cbwsasck.Yxbkov/<>c__DisplayClass0_0::decryptor
ldloc.0 <null>
newobj System.Void Cbwsasck.Asfdwaeisn::.ctor()
stfld Cbwsasck.Asfdwaeisn Cbwsasck.Yxbkov/<>c__DisplayClass0_0::loader
ldloc.0 <null>
ldstr EWPEdOLSx4yM11F1r3.xJXwkgocMlh9EH1GEo
ldstr rBfmgFUso
newobj System.Void Cbwsasck.Egceziw::.ctor(System.String,System.String)
stfld Cbwsasck.Egceziw Cbwsasck.Yxbkov/<>c__DisplayClass0_0::invoker
dup <null>
ldloc.0 <null>
ldftn System.Void Cbwsasck.Yxbkov/<>c__DisplayClass0_0::<Main>b__1(System.IO.MemoryStream)
newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Cbwsasck.Xiwycrb::add_DownloadCompleted(System.Action`1<System.IO.MemoryStream>)
ldloc.0 <null>
ldfld Cbwsasck.Nrlycngwss Cbwsasck.Yxbkov/<>c__DisplayClass0_0::decryptor
ldloc.0 <null>
ldftn System.Void Cbwsasck.Yxbkov/<>c__DisplayClass0_0::<Main>b__2(System.IO.MemoryStream)
newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Cbwsasck.Nrlycngwss::add_DecryptionCompleted(System.Action`1<System.IO.MemoryStream>)
ldloc.0 <null>
ldfld Cbwsasck.Asfdwaeisn Cbwsasck.Yxbkov/<>c__DisplayClass0_0::loader
ldloc.0 <null>
ldftn System.Void Cbwsasck.Yxbkov/<>c__DisplayClass0_0::<Main>b__3(System.Reflection.Assembly)
newobj System.Void System.Action`1<System.Reflection.Assembly>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Cbwsasck.Asfdwaeisn::add_LoadCompleted(System.Action`1<System.Reflection.Assembly>)
ldloc.0 <null>
ldfld Cbwsasck.Egceziw Cbwsasck.Yxbkov/<>c__DisplayClass0_0::invoker
ldsfld System.Action Cbwsasck.Yxbkov/<>c::<>9__0_4
dup <null>
brtrue.s IL_00C8: callvirt System.Void Cbwsasck.Egceziw::add_InvocationCompleted(System.Action)
pop <null>
ldsfld Cbwsasck.Yxbkov/<>c Cbwsasck.Yxbkov/<>c::<>9
ldftn System.Void Cbwsasck.Yxbkov/<>c::<Main>b__0_4()
newobj System.Void System.Action::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.Action Cbwsasck.Yxbkov/<>c::<>9__0_4
callvirt System.Void Cbwsasck.Egceziw::add_InvocationCompleted(System.Action)
callvirt System.Void Cbwsasck.Xiwycrb::Qdgbefrwc()
ret <null>
Module Name
Unvewsmnma
Full Name
Unvewsmnma
EntryPoint
System.Void Cbwsasck.Yxbkov::Main()
Scope Name
Unvewsmnma
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Unvewsmnma
Assembly Version
1.0.7447.5481
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
48
Main Method
System.Void Cbwsasck.Yxbkov::Main()
Main IL Instruction Count
60
Main IL
newobj System.Void Cbwsasck.Yxbkov/<>c__DisplayClass0_0::.ctor()
stloc.0 <null>
ldstr 4H+11ueoUjTdoP4vTzcLzw==
stloc.1 <null>
ldstr VZhmP0Bn1Ok=
stloc.2 <null>
ldsfld System.Func`1<System.Byte[]> Cbwsasck.Yxbkov/<>c::<>9__0_0
dup <null>
brtrue.s IL_0031: newobj System.Void Cbwsasck.Xiwycrb::.ctor(System.Func`1<System.Byte[]>)
pop <null>
ldsfld Cbwsasck.Yxbkov/<>c Cbwsasck.Yxbkov/<>c::<>9
ldftn System.Byte[] Cbwsasck.Yxbkov/<>c::<Main>b__0_0()
newobj System.Void System.Func`1<System.Byte[]>::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.Func`1<System.Byte[]> Cbwsasck.Yxbkov/<>c::<>9__0_0
newobj System.Void Cbwsasck.Xiwycrb::.ctor(System.Func`1<System.Byte[]>)
ldloc.0 <null>
ldloc.1 <null>
ldloc.2 <null>
newobj System.Void Cbwsasck.Nrlycngwss::.ctor(System.String,System.String)
stfld Cbwsasck.Nrlycngwss Cbwsasck.Yxbkov/<>c__DisplayClass0_0::decryptor
ldloc.0 <null>
newobj System.Void Cbwsasck.Asfdwaeisn::.ctor()
stfld Cbwsasck.Asfdwaeisn Cbwsasck.Yxbkov/<>c__DisplayClass0_0::loader
ldloc.0 <null>
ldstr EWPEdOLSx4yM11F1r3.xJXwkgocMlh9EH1GEo
ldstr rBfmgFUso
newobj System.Void Cbwsasck.Egceziw::.ctor(System.String,System.String)
stfld Cbwsasck.Egceziw Cbwsasck.Yxbkov/<>c__DisplayClass0_0::invoker
dup <null>
ldloc.0 <null>
ldftn System.Void Cbwsasck.Yxbkov/<>c__DisplayClass0_0::<Main>b__1(System.IO.MemoryStream)
newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Cbwsasck.Xiwycrb::add_DownloadCompleted(System.Action`1<System.IO.MemoryStream>)
ldloc.0 <null>
ldfld Cbwsasck.Nrlycngwss Cbwsasck.Yxbkov/<>c__DisplayClass0_0::decryptor
ldloc.0 <null>
ldftn System.Void Cbwsasck.Yxbkov/<>c__DisplayClass0_0::<Main>b__2(System.IO.MemoryStream)
newobj System.Void System.Action`1<System.IO.MemoryStream>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Cbwsasck.Nrlycngwss::add_DecryptionCompleted(System.Action`1<System.IO.MemoryStream>)
ldloc.0 <null>
ldfld Cbwsasck.Asfdwaeisn Cbwsasck.Yxbkov/<>c__DisplayClass0_0::loader
ldloc.0 <null>
ldftn System.Void Cbwsasck.Yxbkov/<>c__DisplayClass0_0::<Main>b__3(System.Reflection.Assembly)
newobj System.Void System.Action`1<System.Reflection.Assembly>::.ctor(System.Object,System.IntPtr)
callvirt System.Void Cbwsasck.Asfdwaeisn::add_LoadCompleted(System.Action`1<System.Reflection.Assembly>)
ldloc.0 <null>
ldfld Cbwsasck.Egceziw Cbwsasck.Yxbkov/<>c__DisplayClass0_0::invoker
ldsfld System.Action Cbwsasck.Yxbkov/<>c::<>9__0_4
dup <null>
brtrue.s IL_00C8: callvirt System.Void Cbwsasck.Egceziw::add_InvocationCompleted(System.Action)
pop <null>
ldsfld Cbwsasck.Yxbkov/<>c Cbwsasck.Yxbkov/<>c::<>9
ldftn System.Void Cbwsasck.Yxbkov/<>c::<Main>b__0_4()
newobj System.Void System.Action::.ctor(System.Object,System.IntPtr)
dup <null>
stsfld System.Action Cbwsasck.Yxbkov/<>c::<>9__0_4
callvirt System.Void Cbwsasck.Egceziw::add_InvocationCompleted(System.Action)
callvirt System.Void Cbwsasck.Xiwycrb::Qdgbefrwc()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Cbwsasck.Properties.Resources.resources
Oztdsma
ILRepack.List
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙