Malicious
Malicious

0a898ce55b2e5404d7c1bab841fa6de9

PE Executable
MD5: 0a898ce55b2e5404d7c1bab841fa6de9
Size: 2.71 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 0a898ce55b2e5404d7c1bab841fa6de9
Sha1 498691b47fb699f0589fa0130d61dfecc9fb747e
Sha256 e0a61a28a03edb731c78d4a3f98aa2d3c39e4087d314f55694ae78112a099d86
Sha384 e95d5ef5190abcda70cd77c916a6bec3fac83453bcb8efab862ed24e1ab13ddfaa9560f9eacf4852545bba6418a2bc95
Sha512 ed2506b30111a9082606babfaadd96acab71cc903c473e8093e430457341d7e9c918fd407eb56f503ec13dfde1ac4faa251c90ff994c0d21a5ec4a3f69a8b257
SSDeep 49152:ccEyjKrgywL4wf6AN49lAdv7+azqKbPpFt7MD3L75f108ZuyLAR0fzv4VJajqViz:ccE3FwL4wbC3u7+az3bTNMDU8IVPaee
TLSH 46C52304A64ED513C8634B7605E1F43102B65E4EA972C6ABBFE87DDF39337898491B83
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QW.Bu.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SaltPan.Properties.Resources.resources
IMG
[NBF]root.Data
mjSr
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
meHJ.exe
Full Name
meHJ.exe
EntryPoint
System.Void zPy.XPP::WP4()
Scope Name
meHJ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
meHJ
Assembly Version
201.502.607.709
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
262
Main Method
System.Void zPy.XPP::WP4()
Main IL Instruction Count
15
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0027: nop
nop <null>
ret <null>
call System.Void uPE.WP9::hfy()
br IL_0017: nop
nop <null>
newobj System.Void QW.Bu::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000B: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_000D: call System.Void uPE.WP9::hfy()
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
QW.Bu.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SaltPan.Properties.Resources.resources
IMG
[NBF]root.Data
mjSr
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙