Suspicious
Suspect

f73123dd49c2beaca2cd3de2efc6c7ac

PE Executable
|
MD5: f73123dd49c2beaca2cd3de2efc6c7ac
|
Size: 1.18 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very high

Hash
Hash Value
MD5
f73123dd49c2beaca2cd3de2efc6c7ac
Sha1
a8a89c3b0309d341fd543dc688baf28d72c43bf2
Sha256
cedec56282110dfd147a834510359492d6b5d257d84479a5a197e71c3326e5a8
Sha384
90f41e0f032f73b4ec222137b583f5e149b62598811b194d00cd89c35e451aff8853c025c79692d6aaf200391217a161
Sha512
931de51c4ddbf4bff5c5526bfbb145a077aa3464befa29d7c26706ff89617a47fe61d79f88beae9e32d7a2f0e4668c10d0546e24a975426df555f24e0d683f2e
SSDeep
24576:cgSFJynPgKzfjEXfmRyl/OZbx3PxkA3xcf3SXy:chOPgufjEXf8x3zMB
TLSH
2C45E11163ECDAA8F4BEEB39513805204BF1F917DB22EB1E6E4D41E95831B81DA57323

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Grefagat.rimadon.data
pYd8zs5D6_RcJ1.Resources.resources
0452343622f32a.Resources.resources
5e6938f70
[NBF]root.Data
5e6938f71
[NBF]root.Data
5e6938f710
[NBF]root.Data
5e6938f711
[NBF]root.Data
5e6938f712
[NBF]root.Data
5e6938f713
[NBF]root.Data
5e6938f714
[NBF]root.Data
5e6938f715
[NBF]root.Data
5e6938f716
[NBF]root.Data
5e6938f717
[NBF]root.Data
5e6938f718
[NBF]root.Data
5e6938f719
[NBF]root.Data
5e6938f72
[NBF]root.Data
5e6938f720
[NBF]root.Data
5e6938f721
[NBF]root.Data
5e6938f722
[NBF]root.Data
5e6938f723
[NBF]root.Data
5e6938f73
[NBF]root.Data
5e6938f74
[NBF]root.Data
5e6938f75
[NBF]root.Data
5e6938f76
[NBF]root.Data
5e6938f77
[NBF]root.Data
5e6938f78
[NBF]root.Data
5e6938f79
[NBF]root.Data
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

pYd8zs5D6_RcJ1

Full Name

pYd8zs5D6_RcJ1

EntryPoint

System.Void pYd8zs5D6_RcJ1.2Exxt3dJ::6YbfEo1kgeF53Q()

Scope Name

pYd8zs5D6_RcJ1

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

pYd8zs5D6_RcJ1

Assembly Version

6.17.24.260

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

982

Main Method

System.Void pYd8zs5D6_RcJ1.2Exxt3dJ::6YbfEo1kgeF53Q()

Main IL Instruction Count

153

Main IL

nop <null> nop <null> call System.Int32 System.IntPtr::get_Size() ldc.i4.8 <null> ceq <null> stloc.0 <null> call System.Int32 System.Environment::get_ProcessorCount() stloc.1 <null> ldc.i4.s 25 stloc.2 <null> ldloc.2 <null> ldc.i4.s 23 add.ovf <null> ldc.i4.s 25 div <null> ldc.i4.s 25 mul.ovf <null> stloc.2 <null> ldloc.2 <null> ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newarr System.Object stloc.3 <null> ldloc.2 <null> ldc.i4.2 <null> sub.ovf <null> stloc.s V_15 ldc.i4.0 <null> stloc.s V_16 br.s IL_0043: ldloc.s V_16 ldloc.3 <null> ldloc.s V_16 ldsfld System.DBNull System.DBNull::Value stelem.ref <null> ldloc.s V_16 ldc.i4.1 <null> add.ovf <null> stloc.s V_16 ldloc.s V_16 ldloc.s V_15 ble.s IL_0034: ldloc.3 call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() stloc.s V_4 ldloc.s V_4 callvirt System.String System.Reflection.Assembly::get_Location() stloc.s V_5 ldloc.s V_5 call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) stloc.s V_6 ldloc.s V_6 callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.s V_7 ldloc.s V_7 call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.s V_17 ldloc.s V_17 brfalse.s IL_007F: ldloc.s V_5 ldstr 1.0.0.0 stloc.s V_7 ldloc.s V_5 call System.String System.IO.Path::GetFullPath(System.String) stloc.s V_8 ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) stloc.s V_9 ldloc.s V_9 ldstr SystemTools call System.String System.IO.Path::Combine(System.String,System.String) stloc.s V_10 ldloc.s V_10 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_18 ldloc.s V_18 brfalse.s IL_00B8: nop ldloc.s V_10 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> nop <null> nop <null> ldloc.s V_10 ldstr .initialized call System.String System.IO.Path::Combine(System.String,System.String) stloc.s V_11 ldloc.s V_11 call System.Boolean System.IO.File::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_19 ldloc.s V_19 brfalse.s IL_00F3: nop ldloc.s V_11 call System.DateTime System.DateTime::get_UtcNow() stloc.s V_20 ldloca.s V_20 ldstr o call System.String System.DateTime::ToString(System.String) call System.Void System.IO.File::WriteAllText(System.String,System.String) nop <null> nop <null> nop <null> ldc.i4.s 80 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldstr rimadon.data stloc.s V_12 ldloc.s V_12 ldstr . callvirt System.Boolean System.String::Contains(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_21 ldloc.s V_21 brfalse.s IL_011E: ldloc.s V_12 newobj System.Void System.InvalidOperationException::.ctor() throw <null> ldloc.s V_12 call System.Object pYd8zs5D6_RcJ1.2Exxt3dJ/iMn8e9Ceqd2J.oRq7Eg9bd3g/0diPjWt.wDd24nbFCn1o::zG_56n(System.String) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_13 ldloc.s V_13 ldnull <null> ceq <null> stloc.s V_22 ldloc.s V_22 brfalse.s IL_0139: ldloc.s V_13 leave.s IL_016F: nop ldloc.s V_13 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Object pYd8zs5D6_RcJ1.2Exxt3dJ::2WweikY0N6wny(System.Object) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_14 ldloc.3 <null> ldloc.2 <null> ldc.i4.1 <null> sub.ovf <null> ldloc.s V_14 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stelem.ref <null> ldloc.3 <null> ldloc.2 <null> call System.Void pYd8zs5D6_RcJ1.2Exxt3dJ::gy6RiTm0z7Es(System.Object[],System.Int32) nop <null> leave.s IL_016F: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_016F: nop nop <null> ret <null>

Module Name

pYd8zs5D6_RcJ1

Full Name

pYd8zs5D6_RcJ1

EntryPoint

System.Void pYd8zs5D6_RcJ1.2Exxt3dJ::6YbfEo1kgeF53Q()

Scope Name

pYd8zs5D6_RcJ1

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

pYd8zs5D6_RcJ1

Assembly Version

6.17.24.260

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.6

Total Strings

982

Main Method

System.Void pYd8zs5D6_RcJ1.2Exxt3dJ::6YbfEo1kgeF53Q()

Main IL Instruction Count

153

Main IL

nop <null> nop <null> call System.Int32 System.IntPtr::get_Size() ldc.i4.8 <null> ceq <null> stloc.0 <null> call System.Int32 System.Environment::get_ProcessorCount() stloc.1 <null> ldc.i4.s 25 stloc.2 <null> ldloc.2 <null> ldc.i4.s 23 add.ovf <null> ldc.i4.s 25 div <null> ldc.i4.s 25 mul.ovf <null> stloc.2 <null> ldloc.2 <null> ldc.i4.1 <null> sub.ovf <null> ldc.i4.1 <null> add.ovf <null> newarr System.Object stloc.3 <null> ldloc.2 <null> ldc.i4.2 <null> sub.ovf <null> stloc.s V_15 ldc.i4.0 <null> stloc.s V_16 br.s IL_0043: ldloc.s V_16 ldloc.3 <null> ldloc.s V_16 ldsfld System.DBNull System.DBNull::Value stelem.ref <null> ldloc.s V_16 ldc.i4.1 <null> add.ovf <null> stloc.s V_16 ldloc.s V_16 ldloc.s V_15 ble.s IL_0034: ldloc.3 call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly() stloc.s V_4 ldloc.s V_4 callvirt System.String System.Reflection.Assembly::get_Location() stloc.s V_5 ldloc.s V_5 call System.Diagnostics.FileVersionInfo System.Diagnostics.FileVersionInfo::GetVersionInfo(System.String) stloc.s V_6 ldloc.s V_6 callvirt System.String System.Diagnostics.FileVersionInfo::get_FileVersion() stloc.s V_7 ldloc.s V_7 call System.Boolean System.String::IsNullOrEmpty(System.String) stloc.s V_17 ldloc.s V_17 brfalse.s IL_007F: ldloc.s V_5 ldstr 1.0.0.0 stloc.s V_7 ldloc.s V_5 call System.String System.IO.Path::GetFullPath(System.String) stloc.s V_8 ldc.i4.s 26 call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder) stloc.s V_9 ldloc.s V_9 ldstr SystemTools call System.String System.IO.Path::Combine(System.String,System.String) stloc.s V_10 ldloc.s V_10 call System.Boolean System.IO.Directory::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_18 ldloc.s V_18 brfalse.s IL_00B8: nop ldloc.s V_10 call System.IO.DirectoryInfo System.IO.Directory::CreateDirectory(System.String) pop <null> nop <null> nop <null> ldloc.s V_10 ldstr .initialized call System.String System.IO.Path::Combine(System.String,System.String) stloc.s V_11 ldloc.s V_11 call System.Boolean System.IO.File::Exists(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_19 ldloc.s V_19 brfalse.s IL_00F3: nop ldloc.s V_11 call System.DateTime System.DateTime::get_UtcNow() stloc.s V_20 ldloca.s V_20 ldstr o call System.String System.DateTime::ToString(System.String) call System.Void System.IO.File::WriteAllText(System.String,System.String) nop <null> nop <null> nop <null> ldc.i4.s 80 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> ldstr rimadon.data stloc.s V_12 ldloc.s V_12 ldstr . callvirt System.Boolean System.String::Contains(System.String) ldc.i4.0 <null> ceq <null> stloc.s V_21 ldloc.s V_21 brfalse.s IL_011E: ldloc.s V_12 newobj System.Void System.InvalidOperationException::.ctor() throw <null> ldloc.s V_12 call System.Object pYd8zs5D6_RcJ1.2Exxt3dJ/iMn8e9Ceqd2J.oRq7Eg9bd3g/0diPjWt.wDd24nbFCn1o::zG_56n(System.String) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_13 ldloc.s V_13 ldnull <null> ceq <null> stloc.s V_22 ldloc.s V_22 brfalse.s IL_0139: ldloc.s V_13 leave.s IL_016F: nop ldloc.s V_13 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) call System.Object pYd8zs5D6_RcJ1.2Exxt3dJ::2WweikY0N6wny(System.Object) call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stloc.s V_14 ldloc.3 <null> ldloc.2 <null> ldc.i4.1 <null> sub.ovf <null> ldloc.s V_14 call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object) stelem.ref <null> ldloc.3 <null> ldloc.2 <null> call System.Void pYd8zs5D6_RcJ1.2Exxt3dJ::gy6RiTm0z7Es(System.Object[],System.Int32) nop <null> leave.s IL_016F: nop call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) nop <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_016F: nop nop <null> ret <null>

f73123dd49c2beaca2cd3de2efc6c7ac (1.18 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Grefagat.rimadon.data
pYd8zs5D6_RcJ1.Resources.resources
0452343622f32a.Resources.resources
5e6938f70
[NBF]root.Data
5e6938f71
[NBF]root.Data
5e6938f710
[NBF]root.Data
5e6938f711
[NBF]root.Data
5e6938f712
[NBF]root.Data
5e6938f713
[NBF]root.Data
5e6938f714
[NBF]root.Data
5e6938f715
[NBF]root.Data
5e6938f716
[NBF]root.Data
5e6938f717
[NBF]root.Data
5e6938f718
[NBF]root.Data
5e6938f719
[NBF]root.Data
5e6938f72
[NBF]root.Data
5e6938f720
[NBF]root.Data
5e6938f721
[NBF]root.Data
5e6938f722
[NBF]root.Data
5e6938f723
[NBF]root.Data
5e6938f73
[NBF]root.Data
5e6938f74
[NBF]root.Data
5e6938f75
[NBF]root.Data
5e6938f76
[NBF]root.Data
5e6938f77
[NBF]root.Data
5e6938f78
[NBF]root.Data
5e6938f79
[NBF]root.Data
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙