Malicious
Malicious

0efef11061d189098e3ba4b00f6fd99b

PE Executable
MD5: 0efef11061d189098e3ba4b00f6fd99b
Size: 848.38 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 0efef11061d189098e3ba4b00f6fd99b
Sha1 0f11859d977c2f41e371936cf47b7439c5310394
Sha256 b2ba6f7f09b538de666feaa87bcd10da598f6378c1f2a345ce7e7f854ec41ae9
Sha384 3d6c0b947253e2361957457b5322d3d97e9e82c76858bc107599b46b3ff951d5fa2808e469db2eced24e94f7fbe6abf6
Sha512 19f5fb189b14f482cd71d9711c3b85febe5714c4f098a38ce8e3635189218b95fbef468742d565f799be914be98c12d447a95c407079fd622494c6bb44165dc9
SSDeep 12288:Q1g9ko8CQDc/udYNNNT60Fzm0mnIbJ4EOVGnSTo8b/:QCe7CQ4/udO9Fi0mjcSoa/
TLSH 3505F60A7E48CF01F009163BC2EF494847B49D516AA6E72B7DBA376E55123A73C0D9CB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
rTJWmAgsCoOCdGdSW1.cMoXDLQs3ZWGW3USZf
7FT4v22s5s8vj2DmL1.UZ5dmcJ8VPBwtJjdkX
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Yz4Bh4meR6aLLg3
Full Name
Yz4Bh4meR6aLLg3
EntryPoint
System.Void UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::rbDY7RU8TS()
Scope Name
Yz4Bh4meR6aLLg3
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FJNl2lyUuiEuYH7WkT1R
Assembly Version
7.2.1.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::rbDY7RU8TS()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void HDyafr0J7TU1HeottA8.S2W1Vx0wRrTeMyT0ciU::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::O2cYkyBjP0
callvirt System.Void YmtJHXgw93XaPHYJA3V.XvKD4MgE1FGo2gfSYBE::M8EilXomTb()
nop <null>
ret <null>
Module Name
Yz4Bh4meR6aLLg3
Full Name
Yz4Bh4meR6aLLg3
EntryPoint
System.Void UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::rbDY7RU8TS()
Scope Name
Yz4Bh4meR6aLLg3
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FJNl2lyUuiEuYH7WkT1R
Assembly Version
7.2.1.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::rbDY7RU8TS()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void HDyafr0J7TU1HeottA8.S2W1Vx0wRrTeMyT0ciU::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::O2cYkyBjP0
callvirt System.Void YmtJHXgw93XaPHYJA3V.XvKD4MgE1FGo2gfSYBE::M8EilXomTb()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
rTJWmAgsCoOCdGdSW1.cMoXDLQs3ZWGW3USZf
7FT4v22s5s8vj2DmL1.UZ5dmcJ8VPBwtJjdkX
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙