Malicious
Malicious

18149ead55cb415131241b4ed5559f49

PE Executable
MD5: 18149ead55cb415131241b4ed5559f49
Size: 1.02 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 18149ead55cb415131241b4ed5559f49
Sha1 fe8af3a88ef5559529b4296077defc4738a8344a
Sha256 c0e0b2e9e50a2e015bd89693b4375624a3ec3b1bcf3f6a750c9de79720cae817
Sha384 40375b909cfbbe65f54ea7a47dea49fc130feff0bd5af82e42f981b33dac10972b5185888dcb1cad2262a6ec18b9b1ae
Sha512 4df790144d463096b96be059b0594f26a692e113d6637dd5e94af9ae04ff1da9d017da70896816d93817ea623274805ae24ce8ac39ee5c5cd20f73f9a6421577
SSDeep 12288:hu1L1DSn+sbkYVJx/xFZqmwnjDBip/rqCWi2rqXKg7p5cyi7D9t0:hwgn+sbkwRxbqmI8p/lkWayO7D92
TLSH D0252A017E44CE11F0195233C2EF454847B09A5566F6E72B7DBA376E2A623A73C0DACB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
FSAZ3PYvCAqbXBrAT1.ZoR9ehkPe0pSXrORDX
lVTKxHhr356mvjVFEf.6v1y64tYrIq95m6Eep
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
3TGyiSFwJFg3pUKemSB
Full Name
3TGyiSFwJFg3pUKemSB
EntryPoint
System.Void VOUwmaKcA9Y1wEGy7u0.or8BvLKxZ9IBw869aLa::fB8lkN4IlJ()
Scope Name
3TGyiSFwJFg3pUKemSB
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xwhLnwnbcb3vQsRIjkzHOIB62SEAY
Assembly Version
6.8.9.6
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void VOUwmaKcA9Y1wEGy7u0.or8BvLKxZ9IBw869aLa::fB8lkN4IlJ()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void s3uIeUud3mZsd12SeQi.YoChtMu87KBHc6ZxhK2::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object VOUwmaKcA9Y1wEGy7u0.or8BvLKxZ9IBw869aLa::SySlRxskIO
callvirt System.Void zhgw0yK8A2KFXD2IUk6.H8KUEBKhhMVn8NWVNav::PqOcsVr60D()
nop <null>
ret <null>
Module Name
3TGyiSFwJFg3pUKemSB
Full Name
3TGyiSFwJFg3pUKemSB
EntryPoint
System.Void VOUwmaKcA9Y1wEGy7u0.or8BvLKxZ9IBw869aLa::fB8lkN4IlJ()
Scope Name
3TGyiSFwJFg3pUKemSB
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xwhLnwnbcb3vQsRIjkzHOIB62SEAY
Assembly Version
6.8.9.6
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void VOUwmaKcA9Y1wEGy7u0.or8BvLKxZ9IBw869aLa::fB8lkN4IlJ()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void s3uIeUud3mZsd12SeQi.YoChtMu87KBHc6ZxhK2::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object VOUwmaKcA9Y1wEGy7u0.or8BvLKxZ9IBw869aLa::SySlRxskIO
callvirt System.Void zhgw0yK8A2KFXD2IUk6.H8KUEBKhhMVn8NWVNav::PqOcsVr60D()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
FSAZ3PYvCAqbXBrAT1.ZoR9ehkPe0pSXrORDX
lVTKxHhr356mvjVFEf.6v1y64tYrIq95m6Eep
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙