Malicious
05700e9fe7caa7ffbb63fccc4cff6179
PE Executable
MD5: 05700e9fe7caa7ffbb63fccc4cff6179
Size: 847.36 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 05700e9fe7caa7ffbb63fccc4cff6179 |
| Sha1 | f65f1c971886160a7ab7f706265c9326024f0157 |
| Sha256 | 158dcc5fd88c94f8386ba99f0f77866200fc593f4b35755d357a33ec87fec298 |
| Sha384 | ded6fe41e09709a87ce3045124aa9ac1a5fb69c77b43f24230c104f89dc1b509d7ab9b36db8246893840f20fa6637b52 |
| Sha512 | 0b96f44b9955e8f111ff1fa9682b189b958f777381d0c209a446e17a396c792955b6795aaaaea180011f0b1f3cb8f77ff7f0f9968e02f26639d72cf245e02730 |
| SSDeep | 12288:GLygb83qk14WSI5SUMEEokHmKcBhORXdv20hhGXPIrTHQmN84zx:Gv83zjSpUMEEokHm7+Jc0LG/zmN84t |
| TLSH | 5C05F9017E44CE91F0191673C1EF820847B4A9516AE6E72BBDAE337E55123A73C0E9DB |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
Path
pe:exe>bin
Shape
pe:exe>bin
malicious
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | tt5c184UiCEXj1JC |
| Full Name | tt5c184UiCEXj1JC |
| EntryPoint | System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo() |
| Scope Name | tt5c184UiCEXj1JC |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | bmXk9Ra |
| Assembly Version | 6.5.7.1 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 63 |
| Main Method | System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo() |
| Main IL Instruction Count | 14 |
| Main IL | |
| Module Name | tt5c184UiCEXj1JC |
| Full Name | tt5c184UiCEXj1JC |
| EntryPoint | System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo() |
| Scope Name | tt5c184UiCEXj1JC |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | bmXk9Ra |
| Assembly Version | 6.5.7.1 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 63 |
| Main Method | System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo() |
| Main IL Instruction Count | 14 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.