Malicious
Malicious

191cb0b563270b33b7a53f9ae3007708

PE Executable
MD5: 191cb0b563270b33b7a53f9ae3007708
Size: 915.97 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 191cb0b563270b33b7a53f9ae3007708
Sha1 e0777316c637cbe838d2ba9dc765109ddec1de4e
Sha256 057607c2adbdf0c5b70fb0b146566096eb08ad61ce8c3f85ea2987afedc8dba6
Sha384 75110044cb5be903c4ac02ecb4bf09b28566ea311b99fc9a791042954d0af52675cc26dd57b22584d88def966a00368f
Sha512 58938693b3f037b2b152dd64356f652650a81344ef9d996af26f1f1d4fcca476cc5f2f345ac685ad9eeb3fad41eef80bca18832cd86bfae772941eb5b0e391f4
SSDeep 12288:CLWLcXtVS1cGsx71nsS6nm62kHqFnIVd6CVg/olTBgNSW4Aq:CL7901cGK1nsS6UkHTVd6CVfBg0X
TLSH 1715F6027E44CE51F0091633D2EF494847B4A851AAA6E32B7DFA37BE55523A73C0D9CB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
sh7ddTfa3UIFidqs79.Y8rq4sEprLWysLoLqv
EfQNwk1pk1cloC62pi.VgXLy6I44k32bAUf5w
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
wgj3JzPQsaYbRCHOlCSXYzDD
Full Name
wgj3JzPQsaYbRCHOlCSXYzDD
EntryPoint
System.Void HLJ6EQuZdVybiT86Y7W.qUPvVmuNpoy0aoewHmL::eUDiVTA5tn()
Scope Name
wgj3JzPQsaYbRCHOlCSXYzDD
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
efSa3v58aq
Assembly Version
9.3.0.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void HLJ6EQuZdVybiT86Y7W.qUPvVmuNpoy0aoewHmL::eUDiVTA5tn()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void wIwLlaJ760W0qh8auGX.M5J3cWJwFYgIGlD4C0Z::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object HLJ6EQuZdVybiT86Y7W.qUPvVmuNpoy0aoewHmL::YmMiSpu8O3
callvirt System.Void qxVTPPuwg4cZsdOMaJc.flgGYTu1n4B9S7nTx4j::uo4JwmPC90()
nop <null>
ret <null>
Module Name
wgj3JzPQsaYbRCHOlCSXYzDD
Full Name
wgj3JzPQsaYbRCHOlCSXYzDD
EntryPoint
System.Void HLJ6EQuZdVybiT86Y7W.qUPvVmuNpoy0aoewHmL::eUDiVTA5tn()
Scope Name
wgj3JzPQsaYbRCHOlCSXYzDD
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
efSa3v58aq
Assembly Version
9.3.0.2
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void HLJ6EQuZdVybiT86Y7W.qUPvVmuNpoy0aoewHmL::eUDiVTA5tn()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void wIwLlaJ760W0qh8auGX.M5J3cWJwFYgIGlD4C0Z::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object HLJ6EQuZdVybiT86Y7W.qUPvVmuNpoy0aoewHmL::YmMiSpu8O3
callvirt System.Void qxVTPPuwg4cZsdOMaJc.flgGYTu1n4B9S7nTx4j::uo4JwmPC90()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
sh7ddTfa3UIFidqs79.Y8rq4sEprLWysLoLqv
EfQNwk1pk1cloC62pi.VgXLy6I44k32bAUf5w
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙