Suspicious
Suspect

37a1354d042a6d67dcb4e8d828686fde

PE Executable
MD5: 37a1354d042a6d67dcb4e8d828686fde
Size: 1.13 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 37a1354d042a6d67dcb4e8d828686fde
Sha1 d1ceb3aa43bc79673193a60204018cc515a3db34
Sha256 95efb1bcce48565670cd449762a03676a00a04df82ef14c7391dd4060e98a4ba
Sha384 d8922800783514c4580239ee8478ce23ed22f3044e28fee5befbd8fbaf6ece1ed5c087f6c0b39b1a470d4341628f160f
Sha512 18010da12e0d56f51a191aff1184a78f8a20aeb910487c982f7ce172a94fd90209d6cce9328a5373b016c0ca33ad8e74fc67ed6d84a682e96f2708af5af875b6
SSDeep 12288:7k8gtduziFbSxYnFn++2763vXhg7zPQZA8cs+s0S+TE0T6CYZjAkNfGhZCiaUox2:DKKqbSx4nWiPzAPzTE0OfRAhZ5G9
TLSH 4E35F1291D836F15C73F0E78C166088813F39E168E25E7DB2FEC6DE4BA52B885623553
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Gertali.huta.asp
xy9PC3ocp.Resources.resources
1cdcc13579db55.Resources.resources
1aac39210
[NBF]root.Data
1aac39211
[NBF]root.Data
1aac392110
[NBF]root.Data
1aac392111
[NBF]root.Data
1aac392112
[NBF]root.Data
1aac392113
[NBF]root.Data
1aac392114
[NBF]root.Data
1aac392115
[NBF]root.Data
1aac392116
[NBF]root.Data
1aac392117
[NBF]root.Data
1aac392118
[NBF]root.Data
1aac392119
[NBF]root.Data
1aac39212
[NBF]root.Data
1aac392120
[NBF]root.Data
1aac392121
[NBF]root.Data
1aac392122
[NBF]root.Data
1aac39213
[NBF]root.Data
1aac39214
[NBF]root.Data
1aac39215
[NBF]root.Data
1aac39216
[NBF]root.Data
1aac39217
[NBF]root.Data
1aac39218
[NBF]root.Data
1aac39219
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Module Name
xy9PC3ocp
Full Name
xy9PC3ocp
EntryPoint
System.Void Xrc3a.Kjw9g1gR/eEj17jDoG6.Wen05kQyM3::aTa7jz5()
Scope Name
xy9PC3ocp
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xy9PC3ocp
Assembly Version
15.27.40.62
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Info
PE Detect: PeReader OK (file layout)
Total Strings
0
Main Method
System.Void Xrc3a.Kjw9g1gR/eEj17jDoG6.Wen05kQyM3::aTa7jz5()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void Xrc3a.Kjw9g1gR::.ctor()
stloc.0 <null>
ret <null>
ldtoken System.Void Xrc3a.Kjw9g1gR/eEj17jDoG6.Wen05kQyM3::aTa7jz5()
pop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Gertali.huta.asp
xy9PC3ocp.Resources.resources
1cdcc13579db55.Resources.resources
1aac39210
[NBF]root.Data
1aac39211
[NBF]root.Data
1aac392110
[NBF]root.Data
1aac392111
[NBF]root.Data
1aac392112
[NBF]root.Data
1aac392113
[NBF]root.Data
1aac392114
[NBF]root.Data
1aac392115
[NBF]root.Data
1aac392116
[NBF]root.Data
1aac392117
[NBF]root.Data
1aac392118
[NBF]root.Data
1aac392119
[NBF]root.Data
1aac39212
[NBF]root.Data
1aac392120
[NBF]root.Data
1aac392121
[NBF]root.Data
1aac392122
[NBF]root.Data
1aac39213
[NBF]root.Data
1aac39214
[NBF]root.Data
1aac39215
[NBF]root.Data
1aac39216
[NBF]root.Data
1aac39217
[NBF]root.Data
1aac39218
[NBF]root.Data
1aac39219
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙