Malicious
Malicious

031e2ca44b863fa57d03ee69b3cf6260

PE Executable
MD5: 031e2ca44b863fa57d03ee69b3cf6260
Size: 847.36 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 031e2ca44b863fa57d03ee69b3cf6260
Sha1 634e206a1c4098365af2a08b1fb5972c827a218c
Sha256 089d616e719fe865bfa343a74caeb7eddb1387c020dc51d3d62596bf6a97cabe
Sha384 b7031955297f7c4a6d4432b53556521916b46cd5b66e9e4618aebea6c9d988a88637838ef1a6c246c34c13a5d1a911a6
Sha512 fdc5c7bd0065ecd5f89145ce10ee6d9431fdd523c8e4b7be4ee77d49f8741673db793cf579dd2d7c9545749af2b88a6bcfa9b12dd06065081237732d7ca8a7ea
SSDeep 12288:I0Yu9s2LYgmHRY0t9vfijo8gQFj8EOvNI0S391nxAW0G:RT9vCH+0txifxA91IPt52G
TLSH 1505E7017E84CE12F0091633C2EF854887F4AC91A6A6E72B7DBA376D55123A77C1D9CB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
ksYbgbQOmRwlrvoT6N.XkkR3nteuNsocM0bE3
uBSRXS8koy4KmJdvw0.b1uKEWkvRAKnHcSbFS
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
YGa41sMVHyy7VDR7os7kbUMdJoscq5sIsTSDKGL83cJj
Full Name
YGa41sMVHyy7VDR7os7kbUMdJoscq5sIsTSDKGL83cJj
EntryPoint
System.Void af91T2D98eeqsjo512a.BLoSEyDlOiTZn8jc6Qr::Gp7mEbb0kt()
Scope Name
YGa41sMVHyy7VDR7os7kbUMdJoscq5sIsTSDKGL83cJj
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kt0BjPxjThD
Assembly Version
9.9.7.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void af91T2D98eeqsjo512a.BLoSEyDlOiTZn8jc6Qr::Gp7mEbb0kt()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void t9107bmWeOeFxTpHQ2m.sbs9eemAFvUW4SnlBf6::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object af91T2D98eeqsjo512a.BLoSEyDlOiTZn8jc6Qr::EqOmeZfyl1
callvirt System.Void s9EKexDAYtnBPDqxEJa.KyZPy8DxkihMLDktxb8::Wp10XCkf81()
nop <null>
ret <null>
Module Name
YGa41sMVHyy7VDR7os7kbUMdJoscq5sIsTSDKGL83cJj
Full Name
YGa41sMVHyy7VDR7os7kbUMdJoscq5sIsTSDKGL83cJj
EntryPoint
System.Void af91T2D98eeqsjo512a.BLoSEyDlOiTZn8jc6Qr::Gp7mEbb0kt()
Scope Name
YGa41sMVHyy7VDR7os7kbUMdJoscq5sIsTSDKGL83cJj
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
kt0BjPxjThD
Assembly Version
9.9.7.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void af91T2D98eeqsjo512a.BLoSEyDlOiTZn8jc6Qr::Gp7mEbb0kt()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void t9107bmWeOeFxTpHQ2m.sbs9eemAFvUW4SnlBf6::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object af91T2D98eeqsjo512a.BLoSEyDlOiTZn8jc6Qr::EqOmeZfyl1
callvirt System.Void s9EKexDAYtnBPDqxEJa.KyZPy8DxkihMLDktxb8::Wp10XCkf81()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
ksYbgbQOmRwlrvoT6N.XkkR3nteuNsocM0bE3
uBSRXS8koy4KmJdvw0.b1uKEWkvRAKnHcSbFS
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙