Malicious
191cb0b563270b33b7a53f9ae3007708
PE Executable
MD5: 191cb0b563270b33b7a53f9ae3007708
Size: 915.97 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 191cb0b563270b33b7a53f9ae3007708 |
| Sha1 | e0777316c637cbe838d2ba9dc765109ddec1de4e |
| Sha256 | 057607c2adbdf0c5b70fb0b146566096eb08ad61ce8c3f85ea2987afedc8dba6 |
| Sha384 | 75110044cb5be903c4ac02ecb4bf09b28566ea311b99fc9a791042954d0af52675cc26dd57b22584d88def966a00368f |
| Sha512 | 58938693b3f037b2b152dd64356f652650a81344ef9d996af26f1f1d4fcca476cc5f2f345ac685ad9eeb3fad41eef80bca18832cd86bfae772941eb5b0e391f4 |
| SSDeep | 12288:CLWLcXtVS1cGsx71nsS6nm62kHqFnIVd6CVg/olTBgNSW4Aq:CL7901cGK1nsS6UkHTVd6CVfBg0X |
| TLSH | 1715F6027E44CE51F0091633D2EF494847B4A851AAA6E32B7DFA37BE55523A73C0D9CB |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
Path
pe:exe>bin
Shape
pe:exe>bin
malicious
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | wgj3JzPQsaYbRCHOlCSXYzDD |
| Full Name | wgj3JzPQsaYbRCHOlCSXYzDD |
| EntryPoint | System.Void HLJ6EQuZdVybiT86Y7W.qUPvVmuNpoy0aoewHmL::eUDiVTA5tn() |
| Scope Name | wgj3JzPQsaYbRCHOlCSXYzDD |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | efSa3v58aq |
| Assembly Version | 9.3.0.2 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 63 |
| Main Method | System.Void HLJ6EQuZdVybiT86Y7W.qUPvVmuNpoy0aoewHmL::eUDiVTA5tn() |
| Main IL Instruction Count | 14 |
| Main IL | |
| Module Name | wgj3JzPQsaYbRCHOlCSXYzDD |
| Full Name | wgj3JzPQsaYbRCHOlCSXYzDD |
| EntryPoint | System.Void HLJ6EQuZdVybiT86Y7W.qUPvVmuNpoy0aoewHmL::eUDiVTA5tn() |
| Scope Name | wgj3JzPQsaYbRCHOlCSXYzDD |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | efSa3v58aq |
| Assembly Version | 9.3.0.2 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 63 |
| Main Method | System.Void HLJ6EQuZdVybiT86Y7W.qUPvVmuNpoy0aoewHmL::eUDiVTA5tn() |
| Main IL Instruction Count | 14 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.