Malicious
Malicious

15466030ff72b3d8d13cc121adcd4721

PE Executable
MD5: 15466030ff72b3d8d13cc121adcd4721
Size: 876.03 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 15466030ff72b3d8d13cc121adcd4721
Sha1 6a5585380d5578bd4f47b3da4fdb40aaf27e3f3a
Sha256 c93919b24e82d7c32d8e9f2fa7fc5e3138d21a6360752cc79c7f3f0543ced50d
Sha384 38c12ba30d4ebf16bccb651c6d1d852e84cd3b7fc1d1310eb5b479cc7cc2081b2783273f922a20c6e791f4152a6f79f7
Sha512 498e9e1175f5aa4c6ab01049db760dd8aad6f6f943cc8375218a6b0a5ca03b7360f7f520ff0617278f26f43eefc11abaf3aea141fcbf5bbf50a5d46a9a82a576
SSDeep 24576:xR/TwcWmovlpfPeDoEWR2YCeONIPRXG9o:EllpPezWRe/WPROo
TLSH A41512A65AEEC513E656177349E1E6B103B4DF88F123C75B9EEC7CEB3912B120842781
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
uuI.yup.resources
$this.Icon
[NBF]root.IconData
MR5
[NBF]root.Data
kuM.Cug.resources
SLFE.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
GalacticEmpire4X.Properties.Resources.resources
tfyH
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: SLFE.pdb
Module Name
SLFE.exe
Full Name
SLFE.exe
EntryPoint
System.Void l8.If::SU()
Scope Name
SLFE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
SLFE
Assembly Version
4.2.6.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
69
Main Method
System.Void l8.If::SU()
Main IL Instruction Count
16
Main IL
br IL_001D: nop
call System.Void mbf.Dbc::RyV()
br IL_0028: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void mbf.Dbc::RyV()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0011: nop
nop <null>
newobj System.Void uuI.yup::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000F: nop
Module Name
SLFE.exe
Full Name
SLFE.exe
EntryPoint
System.Void l8.If::SU()
Scope Name
SLFE.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
SLFE
Assembly Version
4.2.6.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
69
Main Method
System.Void l8.If::SU()
Main IL Instruction Count
16
Main IL
br IL_001D: nop
call System.Void mbf.Dbc::RyV()
br IL_0028: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void mbf.Dbc::RyV()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0011: nop
nop <null>
newobj System.Void uuI.yup::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000F: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
uuI.yup.resources
$this.Icon
[NBF]root.IconData
MR5
[NBF]root.Data
kuM.Cug.resources
SLFE.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
GalacticEmpire4X.Properties.Resources.resources
tfyH
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙