Malicious
Malicious

066d8236aa11fb7edf8a7610e8be0e6e

PE Executable
MD5: 066d8236aa11fb7edf8a7610e8be0e6e
Size: 1.7 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 066d8236aa11fb7edf8a7610e8be0e6e
Sha1 6c63ef22c9e1563efa3caca099f42bf2915d22b8
Sha256 8da2763b7ee25e8ecd2b448549f1381c15bfb934653472a09125869b6513cfb8
Sha384 7da7fcc5cd0bee7ec1b04d1ce458daa525891911b02d0d992d36a6a2f558f8386a268978c033ff747819f8c681a9cedc
Sha512 ca76b04cde6daedd408e894876841204824283af57403a7437cd60a2cc4f4731a88f07ad7fe4bb22c64497bc1d411682de8b35bc96d9e095527e880e717c05f9
SSDeep 24576:1MqYjP/2oSdvgWQHXyYCLdWN7kNc13K7spyZMds7jCZOS6WPJIHJe2TnRVjf6gsE:Wb/2oS25HyWNzFYRSDIHJe2TDflsu
TLSH 3F75E0042126DD12D1E25AB0D8E0E2FF16745E83EA11F2439AE67D9FB536784FB846C3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
ec.N8.resources
oJN.nJ0.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
HydroReservoir.Properties.Resources.resources
Pro
[NBF]root.Data
Bnlv
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Module Name
ukEs.exe
Full Name
ukEs.exe
EntryPoint
System.Void XD.kh::Ll()
Scope Name
ukEs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ukEs
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void XD.kh::Ll()
Main IL Instruction Count
16
Main IL
br IL_0011: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_002E: call System.Void suu.OuJ::aLi()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: nop
nop <null>
newobj System.Void ec.N8::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002C: nop
nop <null>
ret <null>
call System.Void suu.OuJ::aLi()
br IL_001C: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
ukEs.exe
Full Name
ukEs.exe
EntryPoint
System.Void XD.kh::Ll()
Scope Name
ukEs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ukEs
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void XD.kh::Ll()
Main IL Instruction Count
16
Main IL
br IL_0011: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_002E: call System.Void suu.OuJ::aLi()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: nop
nop <null>
newobj System.Void ec.N8::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002C: nop
nop <null>
ret <null>
call System.Void suu.OuJ::aLi()
br IL_001C: nop
.Net Resources
ec.N8.resources
oJN.nJ0.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
HydroReservoir.Properties.Resources.resources
Pro
[NBF]root.Data
Bnlv
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙