Malicious
Malicious

11f45214e400e24c21f27371b26d5275

PE Executable
MD5: 11f45214e400e24c21f27371b26d5275
Size: 897.54 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 11f45214e400e24c21f27371b26d5275
Sha1 b1b4795864d07571873b07c9d2a54acb947947b6
Sha256 1a73320195db851f5cfb2869b2b44e28453510e1da7e6a669d7bafbe674da290
Sha384 9099478814561c2fceff728e095748578ae6ee988baa4ec9eafad6b021ac10422b9bd90e4de14ea19e1fdfd0ddd15f23
Sha512 d92e6b961a258793355e15001ca87097b228c882f0782b205c2aa1f7963d7fd5e0ae4fecdccc53e9caf00dede96aa87eb74a25cb258de61603911efdc837552d
SSDeep 12288:KOdR3l6D8o0VVksBFoocikbEG7ZspwxNDE5Goxbls7cTE:/l+8ogJBFoocikJs4NDEsoJq7h
TLSH 3E15F5027E44CE11F4191633C2EF494887B0A9526AA6E32B7DBA776D15133E77C0DACB
PeID
.NET executableHQR data fileMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
U4JwaxoxNgmcw3y79u.eXheqM9SZFLgtl7beT
IbQXj7CbPkUTk5UJGd.O1uTkeWVu4MotLrgsI
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
DvmdeNb9n6Ke
Full Name
DvmdeNb9n6Ke
EntryPoint
System.Void BJjhc49BgaRhTApsJiw.dthg9f9VZG45tRuQtgt::kdbS4yBj0b()
Scope Name
DvmdeNb9n6Ke
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
7yqdN753lmOhzti
Assembly Version
6.0.3.5
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void BJjhc49BgaRhTApsJiw.dthg9f9VZG45tRuQtgt::kdbS4yBj0b()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void SGyEFbSOFTJoB8Bsmak.Vmq51PShe2MiJPgNkm9::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object BJjhc49BgaRhTApsJiw.dthg9f9VZG45tRuQtgt::x5YStNCqXt
callvirt System.Void zTfSwx9henA9XIlQ566.oAXPj79bRjsg5Zv76vn::mlQrwqjHKr()
nop <null>
ret <null>
Module Name
DvmdeNb9n6Ke
Full Name
DvmdeNb9n6Ke
EntryPoint
System.Void BJjhc49BgaRhTApsJiw.dthg9f9VZG45tRuQtgt::kdbS4yBj0b()
Scope Name
DvmdeNb9n6Ke
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
7yqdN753lmOhzti
Assembly Version
6.0.3.5
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void BJjhc49BgaRhTApsJiw.dthg9f9VZG45tRuQtgt::kdbS4yBj0b()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void SGyEFbSOFTJoB8Bsmak.Vmq51PShe2MiJPgNkm9::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object BJjhc49BgaRhTApsJiw.dthg9f9VZG45tRuQtgt::x5YStNCqXt
callvirt System.Void zTfSwx9henA9XIlQ566.oAXPj79bRjsg5Zv76vn::mlQrwqjHKr()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
U4JwaxoxNgmcw3y79u.eXheqM9SZFLgtl7beT
IbQXj7CbPkUTk5UJGd.O1uTkeWVu4MotLrgsI
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙