Malicious
Malicious

37872e46797e86469ac373f572c4b05e

PE Executable
MD5: 37872e46797e86469ac373f572c4b05e
Size: 1.01 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 37872e46797e86469ac373f572c4b05e
Sha1 debca8c651e9919d21c65fa4e88e9216080b862e
Sha256 10e00b5609e2579472202fa80d3f7cb27d3d5f6e975c5497107dde55237b4ae0
Sha384 d1259a4deab2621154092af3f769b9de56a25dd9fe0d3b9a5cf170e11c1c399326e136ddf85471b2f306c174d671598b
Sha512 4fbe2c78d4c08199a488fb16fd42835a462cb76eb47510b7d83ea85e614690d1f14857324a0d258931a9f552134486371ab05acd028b2103a8b3e3fd6d6ec1cb
SSDeep 24576:Ppcvtadrnk1PvuMdyIUGr0ZXpLCXzAS7Ea:BcvOQPXdyq0Z5m9oa
TLSH 49251208262BE903D0B61BB55A93C93553B19E9CE822E04B6FE13FDF397275147A1B43
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ll.Pn.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SaltPan.Properties.Resources.resources
IMG
[NBF]root.Data
SSeh
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
zZxx.exe
Full Name
zZxx.exe
EntryPoint
System.Void z71.t7N::C75()
Scope Name
zZxx.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zZxx
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
262
Main Method
System.Void z71.t7N::C75()
Main IL Instruction Count
15
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0017: nop
nop <null>
ret <null>
call System.Void q7g.B7m::C18()
br IL_0023: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_000D: call System.Void q7g.B7m::C18()
nop <null>
newobj System.Void ll.Pn::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000B: nop
Module Name
zZxx.exe
Full Name
zZxx.exe
EntryPoint
System.Void z71.t7N::C75()
Scope Name
zZxx.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zZxx
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
262
Main Method
System.Void z71.t7N::C75()
Main IL Instruction Count
15
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0017: nop
nop <null>
ret <null>
call System.Void q7g.B7m::C18()
br IL_0023: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_000D: call System.Void q7g.B7m::C18()
nop <null>
newobj System.Void ll.Pn::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000B: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ll.Pn.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SaltPan.Properties.Resources.resources
IMG
[NBF]root.Data
SSeh
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙