099a4dfcf5f7cf48f6b632fe6b5e70ff

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Sep-01 13:21:45
FileDescription
FileVersion 0.0.0.0
InternalName def_net.exe
LegalCopyright
OriginalFilename def_net.exe
ProductVersion 0.0.0.0
Assembly Version 0.0.0.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C# v7.0 / Basic .NET
Malicious VirusTotal score: 34/74 (Scanned on 2024-09-02 01:21:04) ALYac: Gen:Variant.MSILKrypt.19
APEX: Malicious
Arcabit: Trojan.MSILKrypt.19
Avira: TR/Dropper.Gen
BitDefender: Gen:Variant.MSILKrypt.19
BitDefenderTheta: Gen:NN.ZemsilF.36812.3o0@aCviFmi
Bkav: W32.AIDetectMalware.CS
CrowdStrike: win/malicious_confidence_100% (D)
Cybereason: malicious.cf5f7c
Cylance: Unsafe
DeepInstinct: MALICIOUS
DrWeb: Trojan.PackedNET.2595
ESET-NOD32: a variant of MSIL/GenKryptik.FZQG
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.MSILKrypt.19 (B)
F-Secure: Trojan.TR/Dropper.Gen
FireEye: Generic.mg.099a4dfcf5f7cf48
Fortinet: MSIL/GenKryptik.FVDD!tr
GData: Gen:Variant.MSILKrypt.19
Google: Detected
Ikarus: Trojan.Agent
Kaspersky: HEUR:Trojan.Win32.Generic
MAX: malware (ai score=83)
MaxSecure: Trojan.Malware.300983.susgen
McAfeeD: Real Protect-LS!099A4DFCF5F7
MicroWorld-eScan: Gen:Variant.MSILKrypt.19
Microsoft: Trojan:MSIL/AsyncRAT.Z!MTB
Rising: Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:SoL7pYDPnkIzbDUQPSKegg)
SentinelOne: Static AI - Malicious PE
Sophos: ML/PE-A
Symantec: ML.Attribute.HighConfidence
VIPRE: Gen:Variant.MSILKrypt.19
VirIT: Trojan.Win32.MSIL_Heur.A
ZoneAlarm: HEUR:Trojan.Win32.Generic

Hashes

MD5 099a4dfcf5f7cf48f6b632fe6b5e70ff
SHA1 c040fef9c7cd8352e454199212bda54373d7aa30
SHA256 949c87b50682b4e8d450db7c1d66a48a1ec4e6201649fde2e22f58c344e617fe
SHA3 68abd198fc2f137420936a2f58c25a973dc570cd81756b78e2daffb02dc7004e
SSDeep 49152:7vqvd2NVZiC+lzWZtjknV1a++1hAiI7EGRkbY5/kzJNu8l0nd+J5ZMTmoEg:7vqQNVMTotg7a5I7EGG05/k+C0nMJ5Z
Imports Hash f34d5f2d4577ed6d9ceec516c1f5a744

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2024-Sep-01 13:21:45
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 11.0
SizeOfCode 0x2c3c00
SizeOfInitializedData 0x19000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x002C5A8E (Section: .text)
BaseOfCode 0x2000
BaseOfData 0x2c6000
ImageBase 0x400000
SectionAlignment 0x2000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x2e2000
SizeOfHeaders 0x200
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 84916703c4f912ad1ee36fd2e19531b6
SHA1 5f8a6a9d49a0c5a8a48aa08b3672abda5b8d5f10
SHA256 da2ca39f61133e50e60a4253da71439091fc16785220a758de2bcabe8d685cc4
SHA3 bd3345884afbc388ed23436054c9bc1275af8764ee509400e42326be966e998d
VirtualSize 0x2c3a94
VirtualAddress 0x2000
SizeOfRawData 0x2c3c00
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 7.99975

.rsrc

MD5 b4bbfbc02c0d8a66f05825dfb9e7e24f
SHA1 0d1204e61c7828a1b1de8158e3f8e77f789668d3
SHA256 dd582c5c508c536d8d2b6ad30154d8c6aeff7e466be03037acf418f9c20bbc83
SHA3 5f8f41b0d0ecc96baa9b7083d256f1056878c7bcfa3d52f4778437568aa72a13
VirtualSize 0x18c22
VirtualAddress 0x2c6000
SizeOfRawData 0x18e00
PointerToRawData 0x2c3e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.42071

.reloc

MD5 c9546551ca6d1853fdc84850d0f439fa
SHA1 179c5991ddf3c1576e9dd2f09b76f7ba8204fb06
SHA256 a5681e7086da2e8e118ba5088f38388545fb2da2d75724f2b4232eaf868b33a7
SHA3 76f6bc7310c9e42a84856d0b6925e64abf537712afc9d4146420717e1b06a958
VirtualSize 0xc
VirtualAddress 0x2e0000
SizeOfRawData 0x200
PointerToRawData 0x2dcc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.10191

Imports

mscoree.dll _CorExeMain

Delayed Imports

2

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.94789
MD5 bb90b1d436b3a38d1cac274fe1f779fd
SHA1 99ff7ebe859e3ad08ba24d97bb17dc6cd4a86b94
SHA256 cbac98188750aeb018b0e9894286beca737910a1d0bed48a83c31fc69be85294
SHA3 81b3c9794d99b7164aa884daf8d87c965973f16ee52667b707518aa1f085931b

3

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6531
MD5 7729c539f7cec700e408014882f669e2
SHA1 b39c7b877e4e0cab0cca03eee25fce5eba51ded4
SHA256 555ce589696e1964eb8613aac896f524471962643771ec42d0904babfef697f0
SHA3 f339599999d0bf8c10d271904393f397e4273f4efb1bb32774ba3151148b7394

4

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.4759
MD5 c134449cc46c40e1773a327e23f7cc4e
SHA1 3d0bb2b6ba2f82ec172c993d453e7aa99e9e4249
SHA256 6dce0e924ce5f2a5b4b3cdc953afa70c90b37f3b680e572b7b8d5414955f8dfb
SHA3 90b6a2323030e6457bbfdf853ecfff9b41c43b74c155477212ac659b181a9ca9

5

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.3763
MD5 b3b1111dae9ad0e7f3df81651c7f85fa
SHA1 63199716c4fbcdc52e180c4a11a8c6d3fd23579e
SHA256 d101b446bf0b8aa46908a34fa48b3380fda527cc97f717dc2550ea1d3d192938
SHA3 4ebc06a58000f8ac364962424abcfdd1a116eb40bada39bfa03b7f18a2a339c9

6

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.24151
MD5 6d6091ea8a0501e0674852e5c09ac32b
SHA1 c334c76b1d4f23e9a83b01899bb3f96d00df14d5
SHA256 cbbcf0baf270cad60e60f43be6b27f96ac5bcdf57b2bc778d28f3a64ce2a086c
SHA3 21134689961e197533d27976420a4a3b131cf6e6a83cf40d40407db53b6b982b

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.86004
Detected Filetype Icon file
MD5 eebc3c4d6747f0eee70b02c21919e58a
SHA1 9d2145db136050f5602041ca094db336a369e3f3
SHA256 0c1c7e641c92c257480e9065e9d7628cf39ad01e9bc321e37641cd86bf23d8ec
SHA3 84c59f3d3397d8b9c41efea48bce3353eee4872fbab07957e4f04a8c84920b7f

1

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x244
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16065
MD5 9a23a2472671d59c5352a9fe2b8e8b2b
SHA1 3ab1f6f812abb7f5dbe72c913db4f12d35bf0763
SHA256 bdbf59032ccdc8d71e663c1cae1dce3886f749c14d54c0e82740b8f202edd0a5
SHA3 08b155542399587e9cab9fcf490dcd9539467b1425f0139cf5c65d1a0b0b07f2

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x29a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.8746
MD5 691de4b93a7f4feb6a9d85ca68c9cabb
SHA1 f4df2e8344468f35adf63aab97668881528896b0
SHA256 a49308cb7e8b93867003e8ddc96267f99053090267859f7ccd0b6f7095b12251
SHA3 9925a4f8bfe008e0e49fd1d5f485c8f68a5cbefc0e2a3837d9febc64bc49ec5f

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.0.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
FileDescription
FileVersion (#2) 0.0.0.0
InternalName def_net.exe
LegalCopyright
OriginalFilename def_net.exe
ProductVersion (#2) 0.0.0.0
Assembly Version 0.0.0.0
Resource LangID UNKNOWN

TLS Callbacks

Load Configuration

RICH Header

Errors

<-- -->