Suspicious
Suspect

1e41a4c31bbdd0d192b65d9115c69596

Share on LinkedIn
Print
PE Executable
MD5: 1e41a4c31bbdd0d192b65d9115c69596
Size: 155.65 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 1e41a4c31bbdd0d192b65d9115c69596
Sha1 e5e5801cb3c307c9c2971e9b9063d1f5fe2b4f42
Sha256 87f1b3971bb5b44a760fe934c32c9364d1b417fb253da60bee93bf5569f7dc15
Sha384 505ff756f390c61521059de776c4478c8fe48b236a225309a8be12396f9a119947711f85539aa967aa780131149b9cb3
Sha512 459f5f5e7c9b184dd8564fbf4921439385636c08f4ca62e593c2a49f066d7ebfaa1560fe57026971b1818b2a27d5dc93187b27e7b93fdac044dc5a20b0c4ecc9
SSDeep 3072:tzIF0KJuyAXsbRota/g9J/yjgf6yFOBh98EpW6dr757:t0zuyAXsW8/g9Jqm6ysBXrN
TLSH 10E36A82A7F80564FAF77B72BDB246609A377CCAA839D60D1608445D2B33E40DDB1727
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
.Net Resources
office.loader.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
PNG
ID:0000
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:1033-preview.png
ID:0003
ID:1033
ID:1033-preview.png
ID:0004
ID:1033
ID:1033-preview.png
ID:0005
ID:1033
ID:1033-preview.png
ID:0006
ID:1033
ID:1033-preview.png
ID:0007
ID:1033
ID:1033-preview.png
ID:0008
ID:1033
ID:1033-preview.png
RT_STRING
ID:00BC
ID:1033
ID:00BD
ID:1033
ID:00C4
ID:1033
ID:0178
ID:1033
ID:0179
ID:1033
ID:017A
ID:1033
ID:017B
ID:1033
ID:017C
ID:1033
ID:017D
ID:1033
ID:017E
ID:1033
ID:017F
ID:1033
ID:0180
ID:1033
ID:0181
ID:1033
ID:01BC
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
office.exe
Full Name
office.exe
EntryPoint
System.Void office.Program::Main()
Scope Name
office.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
office
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
66
Main Method
System.Void office.Program::Main()
Main IL Instruction Count
31
Main IL
call System.Guid System.Guid::NewGuid()
stloc.1 <null>
ldloca.s V_1
ldstr N
call System.String System.Guid::ToString(System.String)
stloc.0 <null>
ldc.i4.0 <null>
ldstr Global\
ldloc.0 <null>
call System.String System.String::Concat(System.String,System.String)
newobj System.Void System.Threading.Mutex::.ctor(System.Boolean,System.String)
stloc.2 <null>
call System.Byte[] office.Program::GetRawPayload()
stsfld System.Byte[] office.Program::rawShellcode
ldsfld System.Byte[] office.Program::rawShellcode
brfalse.s IL_003E: leave.s IL_0055
ldsfld System.Byte[] office.Program::rawShellcode
ldlen <null>
brtrue.s IL_0040: ldloc.0
leave.s IL_0055: ret
ldloc.0 <null>
call System.Void office.Program::ExecuteControlFlow(System.String)
leave.s IL_0055: ret
pop <null>
leave.s IL_0055: ret
ldloc.2 <null>
brfalse.s IL_0054: endfinally
ldloc.2 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
office.exe
Full Name
office.exe
EntryPoint
System.Void office.Program::Main()
Scope Name
office.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
office
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
66
Main Method
System.Void office.Program::Main()
Main IL Instruction Count
31
Main IL
call System.Guid System.Guid::NewGuid()
stloc.1 <null>
ldloca.s V_1
ldstr N
call System.String System.Guid::ToString(System.String)
stloc.0 <null>
ldc.i4.0 <null>
ldstr Global\
ldloc.0 <null>
call System.String System.String::Concat(System.String,System.String)
newobj System.Void System.Threading.Mutex::.ctor(System.Boolean,System.String)
stloc.2 <null>
call System.Byte[] office.Program::GetRawPayload()
stsfld System.Byte[] office.Program::rawShellcode
ldsfld System.Byte[] office.Program::rawShellcode
brfalse.s IL_003E: leave.s IL_0055
ldsfld System.Byte[] office.Program::rawShellcode
ldlen <null>
brtrue.s IL_0040: ldloc.0
leave.s IL_0055: ret
ldloc.0 <null>
call System.Void office.Program::ExecuteControlFlow(System.String)
leave.s IL_0055: ret
pop <null>
leave.s IL_0055: ret
ldloc.2 <null>
brfalse.s IL_0054: endfinally
ldloc.2 <null>
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙