Suspicious
Suspect

1e41a4c31bbdd0d192b65d9115c69596

PE Executable
MD5: 1e41a4c31bbdd0d192b65d9115c69596
Size: 155.65 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 1e41a4c31bbdd0d192b65d9115c69596
Sha1 e5e5801cb3c307c9c2971e9b9063d1f5fe2b4f42
Sha256 87f1b3971bb5b44a760fe934c32c9364d1b417fb253da60bee93bf5569f7dc15
Sha384 505ff756f390c61521059de776c4478c8fe48b236a225309a8be12396f9a119947711f85539aa967aa780131149b9cb3
Sha512 459f5f5e7c9b184dd8564fbf4921439385636c08f4ca62e593c2a49f066d7ebfaa1560fe57026971b1818b2a27d5dc93187b27e7b93fdac044dc5a20b0c4ecc9
SSDeep 3072:tzIF0KJuyAXsbRota/g9J/yjgf6yFOBh98EpW6dr757:t0zuyAXsW8/g9Jqm6ysBXrN
TLSH 10E36A82A7F80564FAF77B72BDB246609A377CCAA839D60D1608445D2B33E40DDB1727
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
.Net Resources
office.loader.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
PNG
ID:0000
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:1033-preview.png
ID:0003
ID:1033
ID:1033-preview.png
ID:0004
ID:1033
ID:1033-preview.png
ID:0005
ID:1033
ID:1033-preview.png
ID:0006
ID:1033
ID:1033-preview.png
ID:0007
ID:1033
ID:1033-preview.png
ID:0008
ID:1033
ID:1033-preview.png
RT_STRING
ID:00BC
ID:1033
ID:00BD
ID:1033
ID:00C4
ID:1033
ID:0178
ID:1033
ID:0179
ID:1033
ID:017A
ID:1033
ID:017B
ID:1033
ID:017C
ID:1033
ID:017D
ID:1033
ID:017E
ID:1033
ID:017F
ID:1033
ID:0180
ID:1033
ID:0181
ID:1033
ID:01BC
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
office.exe
Full Name
office.exe
EntryPoint
System.Void office.Program::Main()
Scope Name
office.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
office
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
66
Main Method
System.Void office.Program::Main()
Main IL Instruction Count
31
Main IL
call System.Guid System.Guid::NewGuid()
stloc.1 <null>
ldloca.s V_1
ldstr N
call System.String System.Guid::ToString(System.String)
stloc.0 <null>
ldc.i4.0 <null>
ldstr Global\
ldloc.0 <null>
call System.String System.String::Concat(System.String,System.String)
newobj System.Void System.Threading.Mutex::.ctor(System.Boolean,System.String)
stloc.2 <null>
call System.Byte[] office.Program::GetRawPayload()
stsfld System.Byte[] office.Program::rawShellcode
ldsfld System.Byte[] office.Program::rawShellcode
brfalse.s IL_003E: leave.s IL_0055
ldsfld System.Byte[] office.Program::rawShellcode
ldlen <null>
brtrue.s IL_0040: ldloc.0
leave.s IL_0055: ret
ldloc.0 <null>
call System.Void office.Program::ExecuteControlFlow(System.String)
leave.s IL_0055: ret
pop <null>
leave.s IL_0055: ret
ldloc.2 <null>
brfalse.s IL_0054: endfinally
ldloc.2 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
office.exe
Full Name
office.exe
EntryPoint
System.Void office.Program::Main()
Scope Name
office.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
office
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
66
Main Method
System.Void office.Program::Main()
Main IL Instruction Count
31
Main IL
call System.Guid System.Guid::NewGuid()
stloc.1 <null>
ldloca.s V_1
ldstr N
call System.String System.Guid::ToString(System.String)
stloc.0 <null>
ldc.i4.0 <null>
ldstr Global\
ldloc.0 <null>
call System.String System.String::Concat(System.String,System.String)
newobj System.Void System.Threading.Mutex::.ctor(System.Boolean,System.String)
stloc.2 <null>
call System.Byte[] office.Program::GetRawPayload()
stsfld System.Byte[] office.Program::rawShellcode
ldsfld System.Byte[] office.Program::rawShellcode
brfalse.s IL_003E: leave.s IL_0055
ldsfld System.Byte[] office.Program::rawShellcode
ldlen <null>
brtrue.s IL_0040: ldloc.0
leave.s IL_0055: ret
ldloc.0 <null>
call System.Void office.Program::ExecuteControlFlow(System.String)
leave.s IL_0055: ret
pop <null>
leave.s IL_0055: ret
ldloc.2 <null>
brfalse.s IL_0054: endfinally
ldloc.2 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ret <null>
.Net Resources
office.loader.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
PNG
ID:0000
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:1033-preview.png
ID:0003
ID:1033
ID:1033-preview.png
ID:0004
ID:1033
ID:1033-preview.png
ID:0005
ID:1033
ID:1033-preview.png
ID:0006
ID:1033
ID:1033-preview.png
ID:0007
ID:1033
ID:1033-preview.png
ID:0008
ID:1033
ID:1033-preview.png
RT_STRING
ID:00BC
ID:1033
ID:00BD
ID:1033
ID:00C4
ID:1033
ID:0178
ID:1033
ID:0179
ID:1033
ID:017A
ID:1033
ID:017B
ID:1033
ID:017C
ID:1033
ID:017D
ID:1033
ID:017E
ID:1033
ID:017F
ID:1033
ID:0180
ID:1033
ID:0181
ID:1033
ID:01BC
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙