Malicious
Malicious

1453f60f41fba3fbc5dcabd9e95d2ade

PE Executable
MD5: 1453f60f41fba3fbc5dcabd9e95d2ade
Size: 1.73 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 1453f60f41fba3fbc5dcabd9e95d2ade
Sha1 16b436c5f167221c80d30d23db658fba8745088a
Sha256 3d3d00bfe41a79f5b8dc4896a115f8a57f9725b33f771edf0f5c69d813edd5af
Sha384 bcb28a8ea9ef971c87959207a891365dd3185c766a9644fde1bbc0f22ae145ebadf9add618ed764a6862170f28a090ce
Sha512 779f1f14b1a710f6bc897c3f18d11f1f66b4eeadd633df52b46dfae1ee1327b40c1c0969bd948e876ba5801087db25bb10144617d7f85c176bbbd7b20324141c
SSDeep 24576:eZqj0qdPxhw2DQLnzOEqxGkrHV9gXEE5smy28EjU5tIcCRmvBNaYKtj:HXHQLZyXr1SXEtOMRKt
TLSH 948512686317C803D69587744AF2E2B406B94FCBF801D3475FE86FABB636B855D482C2
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ojCc.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
ChurchClock.Properties.Resources.resources
NJ
[NBF]root.Data
h21
[NBF]root.Data
[NBF]root.Data-preview.png
fnJk
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ojCc.exe
Full Name
ojCc.exe
EntryPoint
System.Void spl.npC::zp0()
Scope Name
ojCc.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ojCc
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
183
Main Method
System.Void spl.npC::zp0()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
newobj System.Void M9L.Y9v::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0015: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0023: call System.Void VpB.np3::dl0()
call System.Void VpB.np3::dl0()
br IL_0005: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0017: nop
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ojCc.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
ChurchClock.Properties.Resources.resources
NJ
[NBF]root.Data
h21
[NBF]root.Data
[NBF]root.Data-preview.png
fnJk
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙