Malicious
Malicious

22ce9b4f200c32eeb293116301e97307

PE Executable
MD5: 22ce9b4f200c32eeb293116301e97307
Size: 2.88 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 22ce9b4f200c32eeb293116301e97307
Sha1 7c68c908dddecfa9ad6b4096f81127d46f1ca0d3
Sha256 ad5a8f0a70678395eee394dbe48b2508784e06f37e7a980f4bd61599d180360d
Sha384 99079a00a112fb92f048b3c0c1e8a8bfbc842497ebdabaf5f1d6dea97b7625818f918e42787172461fefcbaead2e9473
Sha512 9096db3768884e61e94c29c0787ab81ccc629635e03e5fcb83b5c319c7be488bd5acb37d2d61281cdc1c8c2e22b3365589f7183760f80ae36614d76086146c73
SSDeep 49152:KYWPh3V0cH0kRHPcEsz/gw3inptdNuW9xLWiYkIX+RPKYwwMz:KTV8APRg/byptdPWcIORPZwX
TLSH 9FD5DF017E46CA01F4191633C2EF855847B1A9516AE6F32BBDBE336D95223973C0E9CB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
wrqCRQGxQKsiGsxCTp.5Dh4PfVExrWDd8TfSP
ppoyFPkqNCEyIJhJsa.twS5t78GkBDIWKb4LF
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
BCC0nu3dQNGaMk
Full Name
BCC0nu3dQNGaMk
EntryPoint
System.Void tBsKaFKc3yGilSgUQKo.OrPHCAKwQA6dFflAPbe::AdruXkPudo()
Scope Name
BCC0nu3dQNGaMk
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CTdU8b8Iu1jtJcuZSq338hmUttiJa9yDWwH8vG6x
Assembly Version
0.9.2.9
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void tBsKaFKc3yGilSgUQKo.OrPHCAKwQA6dFflAPbe::AdruXkPudo()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void pMr2CJu7QaqZLddDbsR.Wl0gcMuOMd2gZdgYYug::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object tBsKaFKc3yGilSgUQKo.OrPHCAKwQA6dFflAPbe::k7ZuAZ5t3W
callvirt System.Void XyK5Z3KOjSga6i5UfxK.zB4c8PKBWiSfA17HPQa::HeO06STkeS()
nop <null>
ret <null>
Module Name
BCC0nu3dQNGaMk
Full Name
BCC0nu3dQNGaMk
EntryPoint
System.Void tBsKaFKc3yGilSgUQKo.OrPHCAKwQA6dFflAPbe::AdruXkPudo()
Scope Name
BCC0nu3dQNGaMk
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CTdU8b8Iu1jtJcuZSq338hmUttiJa9yDWwH8vG6x
Assembly Version
0.9.2.9
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void tBsKaFKc3yGilSgUQKo.OrPHCAKwQA6dFflAPbe::AdruXkPudo()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void pMr2CJu7QaqZLddDbsR.Wl0gcMuOMd2gZdgYYug::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object tBsKaFKc3yGilSgUQKo.OrPHCAKwQA6dFflAPbe::k7ZuAZ5t3W
callvirt System.Void XyK5Z3KOjSga6i5UfxK.zB4c8PKBWiSfA17HPQa::HeO06STkeS()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
wrqCRQGxQKsiGsxCTp.5Dh4PfVExrWDd8TfSP
ppoyFPkqNCEyIJhJsa.twS5t78GkBDIWKb4LF
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙