Malicious
Malicious

127447f106be5f670639649db4c97921

PE Executable
MD5: 127447f106be5f670639649db4c97921
Size: 847.87 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 127447f106be5f670639649db4c97921
Sha1 a94390ce5737291856798a6ca475daf63ca68e7c
Sha256 e28234c87eb635fb36035cc77f95a28eb9327e4161ac10c65501cb335249c7e3
Sha384 bd4c23ac26aab6e4f00fb5bd7535da05d49989bfad12740621a2329023f5072d0e0294bdd61997f5d18e5ec6b7d4c6f7
Sha512 65b8432451c1822732bce5dcafe624b6035068f4f9bd6ab9f98ac90db94dda33a20148676db439dfe8e065ff6aa270cd5ccc3818f53d58bf0b3f7dbde04507e0
SSDeep 24576:/cl+qUNC9iIg8tHdUMoTOjE0imVdiZbddEv:/o+K99wqipU
TLSH EB05F7067E44CE12F0191633C2EF4A4847B49951A6A6E32B7DFA377E55123A73C0DACB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
ScqbEla0eBrcGigTCc.X6VIguQugc9t8A8m7l
emHGbLRxFXk2fbZV1N.D7R9VgFFLvDBtggwVc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
QaQO49FiVmIi2PGupCQYvwUIwVwaZlBt4ZeRTfN
Full Name
QaQO49FiVmIi2PGupCQYvwUIwVwaZlBt4ZeRTfN
EntryPoint
System.Void Ry6cw61wykjAjFX519E.RcCZHg1bNaALumxU5OK::KLVjPxi0AH()
Scope Name
QaQO49FiVmIi2PGupCQYvwUIwVwaZlBt4ZeRTfN
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
E7OB18AlOzHwW3FeGHcjNoIulZncuzbJzeU
Assembly Version
8.5.3.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void Ry6cw61wykjAjFX519E.RcCZHg1bNaALumxU5OK::KLVjPxi0AH()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void LVcNL3hKDsdDXwFbCfm.aNsBGChVq4YCIrFEPhe::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object Ry6cw61wykjAjFX519E.RcCZHg1bNaALumxU5OK::jbPjb78GNK
callvirt System.Void c1mUaG1Vr7QeD03Pq7h.z52P2w1MYCqfhnMAQxR::scfKHS9Z9k()
nop <null>
ret <null>
Module Name
QaQO49FiVmIi2PGupCQYvwUIwVwaZlBt4ZeRTfN
Full Name
QaQO49FiVmIi2PGupCQYvwUIwVwaZlBt4ZeRTfN
EntryPoint
System.Void Ry6cw61wykjAjFX519E.RcCZHg1bNaALumxU5OK::KLVjPxi0AH()
Scope Name
QaQO49FiVmIi2PGupCQYvwUIwVwaZlBt4ZeRTfN
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
E7OB18AlOzHwW3FeGHcjNoIulZncuzbJzeU
Assembly Version
8.5.3.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void Ry6cw61wykjAjFX519E.RcCZHg1bNaALumxU5OK::KLVjPxi0AH()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void LVcNL3hKDsdDXwFbCfm.aNsBGChVq4YCIrFEPhe::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object Ry6cw61wykjAjFX519E.RcCZHg1bNaALumxU5OK::jbPjb78GNK
callvirt System.Void c1mUaG1Vr7QeD03Pq7h.z52P2w1MYCqfhnMAQxR::scfKHS9Z9k()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
ScqbEla0eBrcGigTCc.X6VIguQugc9t8A8m7l
emHGbLRxFXk2fbZV1N.D7R9VgFFLvDBtggwVc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙