Malicious
Malicious

0b66b9342d00ed65aa86f99611f8c086

PE Executable
MD5: 0b66b9342d00ed65aa86f99611f8c086
Size: 1.2 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 0b66b9342d00ed65aa86f99611f8c086
Sha1 564cb7e6aa9040b2fd9bc38a4469fada9f86dfd9
Sha256 245e7f20bf9864307051fd48335c618069fb57253500010623d851f223de923f
Sha384 f3441a4dab6a020d123639e1b5dcdc787a0d2aebad784660a27cb4f9684219ba40c3674d9b5c28e448a1aa8a6db84e9e
Sha512 6dc6957544d510f1f7e095644cb26aa25c0371afe93f24862796735465bb219afefd5b5941655252a407e84b8ab3681e3a80952b7b2743c6d10aec0291b30414
SSDeep 24576:F/qjP/2oSdv6J2gaCBU4ZIzCPt553ndgkiUhYABcMY2rFLHxA4hpA2Nm:8b/2oS0J2gaqtfndgkfBcriFbxfpE
TLSH DD45E0142166DD12D5E25AB0D8E1D2FF02B11D87E811F2039AE57E9FB93A385FB852C3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
cB.jX.resources
mTX.kT2.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
HydroReservoir.Properties.Resources.resources
Pro
[NBF]root.Data
TdIF
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
obQs.exe
Full Name
obQs.exe
EntryPoint
System.Void BD.dM::rv()
Scope Name
obQs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
obQs
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void BD.dM::rv()
Main IL Instruction Count
16
Main IL
br IL_000F: nop
call System.Void ttt.btT::qeM()
br IL_001A: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002C: nop
nop <null>
newobj System.Void cB.jX::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002A: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void ttt.btT::qeM()
Module Name
obQs.exe
Full Name
obQs.exe
EntryPoint
System.Void BD.dM::rv()
Scope Name
obQs.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
obQs
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void BD.dM::rv()
Main IL Instruction Count
16
Main IL
br IL_000F: nop
call System.Void ttt.btT::qeM()
br IL_001A: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002C: nop
nop <null>
newobj System.Void cB.jX::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002A: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void ttt.btT::qeM()
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
cB.jX.resources
mTX.kT2.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
HydroReservoir.Properties.Resources.resources
Pro
[NBF]root.Data
TdIF
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙