Malicious
Malicious

05700e9fe7caa7ffbb63fccc4cff6179

Share on LinkedIn
Print
PE Executable
MD5: 05700e9fe7caa7ffbb63fccc4cff6179
Size: 847.36 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 05700e9fe7caa7ffbb63fccc4cff6179
Sha1 f65f1c971886160a7ab7f706265c9326024f0157
Sha256 158dcc5fd88c94f8386ba99f0f77866200fc593f4b35755d357a33ec87fec298
Sha384 ded6fe41e09709a87ce3045124aa9ac1a5fb69c77b43f24230c104f89dc1b509d7ab9b36db8246893840f20fa6637b52
Sha512 0b96f44b9955e8f111ff1fa9682b189b958f777381d0c209a446e17a396c792955b6795aaaaea180011f0b1f3cb8f77ff7f0f9968e02f26639d72cf245e02730
SSDeep 12288:GLygb83qk14WSI5SUMEEokHmKcBhORXdv20hhGXPIrTHQmN84zx:Gv83zjSpUMEEokHm7+Jc0LG/zmN84t
TLSH 5C05F9017E44CE91F0191673C1EF820847B4A9516AE6E72BBDAE337E55123A73C0E9DB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
Ubr8suuSMPNojUloJB.VUFq8rdIuuXCZv45nk
dXoyYDN279tQ4plk2Y.CQ8CpGY4X5vNhYSEIw
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
tt5c184UiCEXj1JC
Full Name
tt5c184UiCEXj1JC
EntryPoint
System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo()
Scope Name
tt5c184UiCEXj1JC
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bmXk9Ra
Assembly Version
6.5.7.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void jm7SWJ8HOmxNZGTpA36.getsha89epmikjVbWOX::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::fvi3xDA4pA
callvirt System.Void dG9fNyS9KmRMVPE63mF.U2geGRSq4oKnidaov0o::oPCfIxewhP()
nop <null>
ret <null>
Module Name
tt5c184UiCEXj1JC
Full Name
tt5c184UiCEXj1JC
EntryPoint
System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo()
Scope Name
tt5c184UiCEXj1JC
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
bmXk9Ra
Assembly Version
6.5.7.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::RKs3r7QqNo()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void jm7SWJ8HOmxNZGTpA36.getsha89epmikjVbWOX::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object oWOo0hSleIoJClxBjC1.APstmESa1kGgIiiHrxP::fvi3xDA4pA
callvirt System.Void dG9fNyS9KmRMVPE63mF.U2geGRSq4oKnidaov0o::oPCfIxewhP()
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙