Malicious
Malicious

fb79bc487e71ccad7920d343bd20daec

PE Executable
MD5: fb79bc487e71ccad7920d343bd20daec
Size: 3.52 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 fb79bc487e71ccad7920d343bd20daec
Sha1 3b56fcb127d7405b5706a8ff863b96f69dab10ad
Sha256 d3bb065bfedeb380a97b8c445cd699bc2a275b30814d8f3aca049462f1928360
Sha384 8b57b13ccdfac95615ceed960f86b8c520c95cbf926378b89d9b837b3d820f67120f99ea131df919455f49e19ca6002d
Sha512 2ab22dd373b3a87dfc03791417b11482d7866b75f6cb9289a7bb96cfd1e07bb04964e6b1ab4272bc54ce194c79564bd82b43236a9da5d771523d22cad0c9fb11
SSDeep 49152:MomDeFCSAsma+zXgWx8yErRg5Qf/UYsJU6Io3yugiwCk+xF:MomD6PAsCTmcFZ3qiDF
TLSH A9F54A13FACF5E72C644B77AD5F7042267A1E742A327C35B6A0AA3199C4B76B5F00183
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Pkznz.Properties.Resources.resources
Jwnmv
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Btgrbedcm.exe
Full Name
Btgrbedcm.exe
EntryPoint
System.Void SteamKit2.Iterators.VisibleIterator::SendIterator()
Scope Name
Btgrbedcm.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Btgrbedcm
Assembly Version
1.0.2825.15460
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1291
Main Method
System.Void SteamKit2.Iterators.VisibleIterator::SendIterator()
Main IL Instruction Count
18
Main IL
ldc.i4 1
stloc V_0
br IL_000E: ldloc V_0
ldloc V_0
switch dnlib.DotNet.Emit.Instruction[]
br IL_0024: ret
ret <null>
newobj System.Void Btgrbedcm.ContextManagement.SetContext::.ctor()
call System.Byte[] Btgrbedcm.ContextManagement.SetContext::FilterVisibleContext()
call System.Byte[] Btgrbedcm.Processing.CentralCollector::GetCombinedCollector(System.Object)
call System.Void SteamKit2.Collectors.ReceiverManager::ReceiveIntegratedReceiver(System.Object)
ldc.i4 0
ldsfld <Module>{d10fed0d-8008-4cb3-a622-007e64cd8ea7} <Module>{d10fed0d-8008-4cb3-a622-007e64cd8ea7}::m_1fef0b89324d4c19b75016fc7972a4fb
ldfld System.Int32 <Module>{d10fed0d-8008-4cb3-a622-007e64cd8ea7}::m_12ad8d7964924582bb9391f52a37985b
brtrue IL_0012: switch(IL_0024,IL_0025)
pop <null>
ldc.i4 0
br IL_0012: switch(IL_0024,IL_0025)
Module Name
Btgrbedcm.exe
Full Name
Btgrbedcm.exe
EntryPoint
System.Void SteamKit2.Iterators.VisibleIterator::SendIterator()
Scope Name
Btgrbedcm.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Btgrbedcm
Assembly Version
1.0.2825.15460
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1291
Main Method
System.Void SteamKit2.Iterators.VisibleIterator::SendIterator()
Main IL Instruction Count
18
Main IL
ldc.i4 1
stloc V_0
br IL_000E: ldloc V_0
ldloc V_0
switch dnlib.DotNet.Emit.Instruction[]
br IL_0024: ret
ret <null>
newobj System.Void Btgrbedcm.ContextManagement.SetContext::.ctor()
call System.Byte[] Btgrbedcm.ContextManagement.SetContext::FilterVisibleContext()
call System.Byte[] Btgrbedcm.Processing.CentralCollector::GetCombinedCollector(System.Object)
call System.Void SteamKit2.Collectors.ReceiverManager::ReceiveIntegratedReceiver(System.Object)
ldc.i4 0
ldsfld <Module>{d10fed0d-8008-4cb3-a622-007e64cd8ea7} <Module>{d10fed0d-8008-4cb3-a622-007e64cd8ea7}::m_1fef0b89324d4c19b75016fc7972a4fb
ldfld System.Int32 <Module>{d10fed0d-8008-4cb3-a622-007e64cd8ea7}::m_12ad8d7964924582bb9391f52a37985b
brtrue IL_0012: switch(IL_0024,IL_0025)
pop <null>
ldc.i4 0
br IL_0012: switch(IL_0024,IL_0025)
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Pkznz.Properties.Resources.resources
Jwnmv
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙