Suspicious
Suspect

07f50d7334f97c8322d3b1a457b3347c

PE Executable
MD5: 07f50d7334f97c8322d3b1a457b3347c
Size: 1.07 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 07f50d7334f97c8322d3b1a457b3347c
Sha1 d76dd8084c5d023a6c0fd9a0867e19058d95ca8c
Sha256 fb0889110aec73085c455f345f4f920d68aec7ae70f84867c57c9ca0e49b9564
Sha384 49814c55cfc4e3a28f2833108308e97372e256ec6de8eb29fca6b727c63df8cc531c9c7fe389216e9a15a2369f2c61ba
Sha512 bbeb5b57719fb8d6c8870246bbfa8d06836e188b35e7c0f642770b7bc48a3df6cf0e67049d9bc1c9fd0b3f59a364d9a370ea6b328b851afa96db6c9ef6a5fb15
SSDeep 12288:StpI2Sx1Ti8Wc/VYhzjP2QNO66in2AMhApzP6vaiARO7bL4e7QXl6o:StpdYocNYtfO66i2NhQzi5IO7bL4
TLSH 0735DF1523D89F58E9BF9739593555144BF3BD069E32D3EE3E8C2CD93A31A408A22723
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Et6e7odMpeP9x0.g.resources
Et6e7odMpeP9x0.Resources.resources
11bb87534692b3.Resources.resources
9cf31cf30
[NBF]root.Data
9cf31cf31
[NBF]root.Data
9cf31cf310
[NBF]root.Data
9cf31cf311
[NBF]root.Data
9cf31cf312
[NBF]root.Data
9cf31cf313
[NBF]root.Data
9cf31cf314
[NBF]root.Data
9cf31cf315
[NBF]root.Data
9cf31cf316
[NBF]root.Data
9cf31cf317
[NBF]root.Data
9cf31cf318
[NBF]root.Data
9cf31cf319
[NBF]root.Data
9cf31cf32
[NBF]root.Data
9cf31cf320
[NBF]root.Data
9cf31cf321
[NBF]root.Data
9cf31cf322
[NBF]root.Data
9cf31cf323
[NBF]root.Data
9cf31cf324
[NBF]root.Data
9cf31cf33
[NBF]root.Data
9cf31cf34
[NBF]root.Data
9cf31cf35
[NBF]root.Data
9cf31cf36
[NBF]root.Data
9cf31cf37
[NBF]root.Data
9cf31cf38
[NBF]root.Data
9cf31cf39
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Et6e7odMpeP9x0
Full Name
Et6e7odMpeP9x0
EntryPoint
System.Void Et6e7odMpeP9x0.me6G9zXiyJ1k4::Rqz2q8jCHsb4()
Scope Name
Et6e7odMpeP9x0
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Et6e7odMpeP9x0
Assembly Version
29.26.15.11
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
783
Main Method
System.Void Et6e7odMpeP9x0.me6G9zXiyJ1k4::Rqz2q8jCHsb4()
Main IL Instruction Count
30
Main IL
nop <null>
nop <null>
ldc.i4.s 25
stloc.0 <null>
ldloc.0 <null>
ldc.i4.1 <null>
sub.ovf <null>
ldc.i4.1 <null>
add.ovf <null>
newarr System.Object
stloc.1 <null>
ldloc.1 <null>
ldloc.0 <null>
call System.Void Et6e7odMpeP9x0.me6G9zXiyJ1k4::Kgx98m(System.Object[],System.Int32)
nop <null>
leave.s IL_0037: nop
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
nop <null>
ldloc.2 <null>
callvirt System.String System.Exception::ToString()
ldc.i4.0 <null>
ldnull <null>
call Microsoft.VisualBasic.MsgBoxResult Microsoft.VisualBasic.Interaction::MsgBox(System.Object,Microsoft.VisualBasic.MsgBoxStyle,System.Object)
pop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0037: nop
nop <null>
ret <null>
Module Name
Et6e7odMpeP9x0
Full Name
Et6e7odMpeP9x0
EntryPoint
System.Void Et6e7odMpeP9x0.me6G9zXiyJ1k4::Rqz2q8jCHsb4()
Scope Name
Et6e7odMpeP9x0
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Et6e7odMpeP9x0
Assembly Version
29.26.15.11
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
783
Main Method
System.Void Et6e7odMpeP9x0.me6G9zXiyJ1k4::Rqz2q8jCHsb4()
Main IL Instruction Count
30
Main IL
nop <null>
nop <null>
ldc.i4.s 25
stloc.0 <null>
ldloc.0 <null>
ldc.i4.1 <null>
sub.ovf <null>
ldc.i4.1 <null>
add.ovf <null>
newarr System.Object
stloc.1 <null>
ldloc.1 <null>
ldloc.0 <null>
call System.Void Et6e7odMpeP9x0.me6G9zXiyJ1k4::Kgx98m(System.Object[],System.Int32)
nop <null>
leave.s IL_0037: nop
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
nop <null>
ldloc.2 <null>
callvirt System.String System.Exception::ToString()
ldc.i4.0 <null>
ldnull <null>
call Microsoft.VisualBasic.MsgBoxResult Microsoft.VisualBasic.Interaction::MsgBox(System.Object,Microsoft.VisualBasic.MsgBoxStyle,System.Object)
pop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0037: nop
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Et6e7odMpeP9x0.g.resources
Et6e7odMpeP9x0.Resources.resources
11bb87534692b3.Resources.resources
9cf31cf30
[NBF]root.Data
9cf31cf31
[NBF]root.Data
9cf31cf310
[NBF]root.Data
9cf31cf311
[NBF]root.Data
9cf31cf312
[NBF]root.Data
9cf31cf313
[NBF]root.Data
9cf31cf314
[NBF]root.Data
9cf31cf315
[NBF]root.Data
9cf31cf316
[NBF]root.Data
9cf31cf317
[NBF]root.Data
9cf31cf318
[NBF]root.Data
9cf31cf319
[NBF]root.Data
9cf31cf32
[NBF]root.Data
9cf31cf320
[NBF]root.Data
9cf31cf321
[NBF]root.Data
9cf31cf322
[NBF]root.Data
9cf31cf323
[NBF]root.Data
9cf31cf324
[NBF]root.Data
9cf31cf33
[NBF]root.Data
9cf31cf34
[NBF]root.Data
9cf31cf35
[NBF]root.Data
9cf31cf36
[NBF]root.Data
9cf31cf37
[NBF]root.Data
9cf31cf38
[NBF]root.Data
9cf31cf39
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙