Malicious
Malicious

1fa24618993a4828e566da20b40bb181

PE Executable
MD5: 1fa24618993a4828e566da20b40bb181
Size: 3.16 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 1fa24618993a4828e566da20b40bb181
Sha1 50ab6fa03c74aac498627a9949d88931f4b15fd8
Sha256 c6d374bf20c20fd3a1b14a1e8a8334c41cdf9c3098bc2f8b1afbec7ac43881af
Sha384 021b9416cbfeae04275c8c0f9ec0dd4a6d791d109d075efb6c32e978f127b30b593e4496cdb72e8d35a4e602765606f9
Sha512 e727155509137fe679eb439247c49ed9b0adb151488343d9e9c662d275f2ad26f9415675fa94ac8a54f1476c44620f2c4753bc30d72eb14f0ae280c9b33095db
SSDeep 49152:lbmWzE76l0fkja0SoqNLhpzMj8pb0inLKopH6F46i2hD30nTkcRLHf7:8W0fkjxMLA81nLKop16itTZL/7
TLSH 89E5E0017E44CE12F0181273C2EF458887B4AA516AA6E32B7DFA377E55523973C0DACB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
VJoYe8EufLyZMMQ7th.8HRkgHkrYlf0Ut4nXL
dZEE1ml87ZdCMf1Fj4.n7BMeg9VPYoXZFuFIP
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
dMrCVm
Full Name
dMrCVm
EntryPoint
System.Void z4qIabgImSMLATpXVKh.O0OoHNg2bYgAOVgOpkS::D9CWb1BKdB()
Scope Name
dMrCVm
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
MerVk9a56WGspXNc6CSjWmGahjiU
Assembly Version
8.8.7.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void z4qIabgImSMLATpXVKh.O0OoHNg2bYgAOVgOpkS::D9CWb1BKdB()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void Pv2lDF0LG4Jeq81ldG9.nmdwE10EttS9Ek0AZvE::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object z4qIabgImSMLATpXVKh.O0OoHNg2bYgAOVgOpkS::V8bW5WRSh4
callvirt System.Void YCeg7IgEVrEdcMwtB5K.CeKltGg5aVKTgpFVVww::vkxEnoGeMK()
nop <null>
ret <null>
Module Name
dMrCVm
Full Name
dMrCVm
EntryPoint
System.Void z4qIabgImSMLATpXVKh.O0OoHNg2bYgAOVgOpkS::D9CWb1BKdB()
Scope Name
dMrCVm
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
MerVk9a56WGspXNc6CSjWmGahjiU
Assembly Version
8.8.7.4
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void z4qIabgImSMLATpXVKh.O0OoHNg2bYgAOVgOpkS::D9CWb1BKdB()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void Pv2lDF0LG4Jeq81ldG9.nmdwE10EttS9Ek0AZvE::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object z4qIabgImSMLATpXVKh.O0OoHNg2bYgAOVgOpkS::V8bW5WRSh4
callvirt System.Void YCeg7IgEVrEdcMwtB5K.CeKltGg5aVKTgpFVVww::vkxEnoGeMK()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
VJoYe8EufLyZMMQ7th.8HRkgHkrYlf0Ut4nXL
dZEE1ml87ZdCMf1Fj4.n7BMeg9VPYoXZFuFIP
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙