Malicious
Malicious

05700e9fe7caa7ffbb63fccc4cff6179

PE Executable
MD5: 05700e9fe7caa7ffbb63fccc4cff6179
Size: 847.36 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 05700e9fe7caa7ffbb63fccc4cff6179
Sha1 f65f1c971886160a7ab7f706265c9326024f0157
Sha256 158dcc5fd88c94f8386ba99f0f77866200fc593f4b35755d357a33ec87fec298
Sha384 ded6fe41e09709a87ce3045124aa9ac1a5fb69c77b43f24230c104f89dc1b509d7ab9b36db8246893840f20fa6637b52
Sha512 0b96f44b9955e8f111ff1fa9682b189b958f777381d0c209a446e17a396c792955b6795aaaaea180011f0b1f3cb8f77ff7f0f9968e02f26639d72cf245e02730
SSDeep 12288:GLygb83qk14WSI5SUMEEokHmKcBhORXdv20hhGXPIrTHQmN84zx:Gv83zjSpUMEEokHm7+Jc0LG/zmN84t
TLSH 5C05F9017E44CE91F0191673C1EF820847B4A9516AE6E72BBDAE337E55123A73C0E9DB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
Ubr8suuSMPNojUloJB.VUFq8rdIuuXCZv45nk
dXoyYDN279tQ4plk2Y.CQ8CpGY4X5vNhYSEIw
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
tt5c184UiCEXj1JC
Full Name
tt5c184UiCEXj1JC
EntryPoint
System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo()
Scope Name
tt5c184UiCEXj1JC
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bmXk9Ra
Assembly Version
6.5.7.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void jm7SWJ8HOmxNZGTpA36.getsha89epmikjVbWOX::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::fvi3xDA4pA
callvirt System.Void dG9fNyS9KmRMVPE63mF.U2geGRSq4oKnidaov0o::oPCfIxewhP()
nop <null>
ret <null>
Module Name
tt5c184UiCEXj1JC
Full Name
tt5c184UiCEXj1JC
EntryPoint
System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo()
Scope Name
tt5c184UiCEXj1JC
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bmXk9Ra
Assembly Version
6.5.7.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void jm7SWJ8HOmxNZGTpA36.getsha89epmikjVbWOX::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::fvi3xDA4pA
callvirt System.Void dG9fNyS9KmRMVPE63mF.U2geGRSq4oKnidaov0o::oPCfIxewhP()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
Ubr8suuSMPNojUloJB.VUFq8rdIuuXCZv45nk
dXoyYDN279tQ4plk2Y.CQ8CpGY4X5vNhYSEIw
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙