Malicious
Malicious

0efef11061d189098e3ba4b00f6fd99b

Share on LinkedIn
Print
PE Executable
MD5: 0efef11061d189098e3ba4b00f6fd99b
Size: 848.38 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 0efef11061d189098e3ba4b00f6fd99b
Sha1 0f11859d977c2f41e371936cf47b7439c5310394
Sha256 b2ba6f7f09b538de666feaa87bcd10da598f6378c1f2a345ce7e7f854ec41ae9
Sha384 3d6c0b947253e2361957457b5322d3d97e9e82c76858bc107599b46b3ff951d5fa2808e469db2eced24e94f7fbe6abf6
Sha512 19f5fb189b14f482cd71d9711c3b85febe5714c4f098a38ce8e3635189218b95fbef468742d565f799be914be98c12d447a95c407079fd622494c6bb44165dc9
SSDeep 12288:Q1g9ko8CQDc/udYNNNT60Fzm0mnIbJ4EOVGnSTo8b/:QCe7CQ4/udO9Fi0mjcSoa/
TLSH 3505F60A7E48CF01F009163BC2EF494847B49D516AA6E72B7DBA376E55123A73C0D9CB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
rTJWmAgsCoOCdGdSW1.cMoXDLQs3ZWGW3USZf
7FT4v22s5s8vj2DmL1.UZ5dmcJ8VPBwtJjdkX
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Yz4Bh4meR6aLLg3
Full Name
Yz4Bh4meR6aLLg3
EntryPoint
System.Void UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::rbDY7RU8TS()
Scope Name
Yz4Bh4meR6aLLg3
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FJNl2lyUuiEuYH7WkT1R
Assembly Version
7.2.1.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::rbDY7RU8TS()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void HDyafr0J7TU1HeottA8.S2W1Vx0wRrTeMyT0ciU::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::O2cYkyBjP0
callvirt System.Void YmtJHXgw93XaPHYJA3V.XvKD4MgE1FGo2gfSYBE::M8EilXomTb()
nop <null>
ret <null>
Module Name
Yz4Bh4meR6aLLg3
Full Name
Yz4Bh4meR6aLLg3
EntryPoint
System.Void UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::rbDY7RU8TS()
Scope Name
Yz4Bh4meR6aLLg3
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FJNl2lyUuiEuYH7WkT1R
Assembly Version
7.2.1.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::rbDY7RU8TS()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void HDyafr0J7TU1HeottA8.S2W1Vx0wRrTeMyT0ciU::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object UiglC0gIGI7wpcb5epX.mVi0G5g3Sl2kYKdl3w8::O2cYkyBjP0
callvirt System.Void YmtJHXgw93XaPHYJA3V.XvKD4MgE1FGo2gfSYBE::M8EilXomTb()
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙