Malicious
Malicious

19218b199b1706d1e1f4416ffb1b27cf

PE Executable
MD5: 19218b199b1706d1e1f4416ffb1b27cf
Size: 847.87 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 19218b199b1706d1e1f4416ffb1b27cf
Sha1 b61cb466e36c1a047159ced3f2317ba189940af3
Sha256 24fdc48249a04de295cbcc222a9da62ecffdf60cee25c3879bf12ccab3393282
Sha384 4aad074046be79e120d7b7c1d79d4335327815b73bc2c6e5d59e02d9db3220e49ba7642f8bbb88f3f2cd3d60d41113b7
Sha512 33dd2df388462567ce2c4964c124245d9e31bcf625c971b185b2f311c9cc12136f5335961cfb7cea89ac4b693609865a16eb9535fe7f9dfcba8e5192700e0c38
SSDeep 12288:Udr6HUM9ev4KM7FNj5UDjyq6M273IDf+Wz64Zjj9AArt65:Ud4UM9iMJNjG38CDfz64ZX9DE5
TLSH 650508417E44CE01F0095A33C2EF55488BB09D5166AAE32B7DBE37AE25123977C0DADB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
dASZ8PUoIV3PMHDgVZ.OVv35nxBGUs9ej53Vx
u9WvH346QTqPUv4kSa.yslwVKnSUOgKfi10H6
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
aJLkWhclJI5O
Full Name
aJLkWhclJI5O
EntryPoint
System.Void YNQZcXB6FjtfUIOvupv.lXoCMaBron18IT9J1Yk::aA7IpqvdKX()
Scope Name
aJLkWhclJI5O
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Hu8IbbGU9SNar9rDZRcPp0wK9ICCqSw3Ab
Assembly Version
5.5.8.7
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void YNQZcXB6FjtfUIOvupv.lXoCMaBron18IT9J1Yk::aA7IpqvdKX()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void RVClOcj5Fjle1cngaE2.x4TWLWjtWq55gtqxkS4::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object YNQZcXB6FjtfUIOvupv.lXoCMaBron18IT9J1Yk::LZKIWn4m30
callvirt System.Void t9AgMsBtVWZYLiSEh4f.tVo9KgBcOYoQbTM5yNF::tnIsn1R3ed()
nop <null>
ret <null>
Module Name
aJLkWhclJI5O
Full Name
aJLkWhclJI5O
EntryPoint
System.Void YNQZcXB6FjtfUIOvupv.lXoCMaBron18IT9J1Yk::aA7IpqvdKX()
Scope Name
aJLkWhclJI5O
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Hu8IbbGU9SNar9rDZRcPp0wK9ICCqSw3Ab
Assembly Version
5.5.8.7
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void YNQZcXB6FjtfUIOvupv.lXoCMaBron18IT9J1Yk::aA7IpqvdKX()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void RVClOcj5Fjle1cngaE2.x4TWLWjtWq55gtqxkS4::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object YNQZcXB6FjtfUIOvupv.lXoCMaBron18IT9J1Yk::LZKIWn4m30
callvirt System.Void t9AgMsBtVWZYLiSEh4f.tVo9KgBcOYoQbTM5yNF::tnIsn1R3ed()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
dASZ8PUoIV3PMHDgVZ.OVv35nxBGUs9ej53Vx
u9WvH346QTqPUv4kSa.yslwVKnSUOgKfi10H6
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙