Suspicious
Suspect

37a1354d042a6d67dcb4e8d828686fde

Share on LinkedIn
Print
PE Executable
MD5: 37a1354d042a6d67dcb4e8d828686fde
Size: 1.13 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 37a1354d042a6d67dcb4e8d828686fde
Sha1 d1ceb3aa43bc79673193a60204018cc515a3db34
Sha256 95efb1bcce48565670cd449762a03676a00a04df82ef14c7391dd4060e98a4ba
Sha384 d8922800783514c4580239ee8478ce23ed22f3044e28fee5befbd8fbaf6ece1ed5c087f6c0b39b1a470d4341628f160f
Sha512 18010da12e0d56f51a191aff1184a78f8a20aeb910487c982f7ce172a94fd90209d6cce9328a5373b016c0ca33ad8e74fc67ed6d84a682e96f2708af5af875b6
SSDeep 12288:7k8gtduziFbSxYnFn++2763vXhg7zPQZA8cs+s0S+TE0T6CYZjAkNfGhZCiaUox2:DKKqbSx4nWiPzAPzTE0OfRAhZ5G9
TLSH 4E35F1291D836F15C73F0E78C166088813F39E168E25E7DB2FEC6DE4BA52B885623553
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Gertali.huta.asp
xy9PC3ocp.Resources.resources
1cdcc13579db55.Resources.resources
1aac39210
[NBF]root.Data
1aac39211
[NBF]root.Data
1aac392110
[NBF]root.Data
1aac392111
[NBF]root.Data
1aac392112
[NBF]root.Data
1aac392113
[NBF]root.Data
1aac392114
[NBF]root.Data
1aac392115
[NBF]root.Data
1aac392116
[NBF]root.Data
1aac392117
[NBF]root.Data
1aac392118
[NBF]root.Data
1aac392119
[NBF]root.Data
1aac39212
[NBF]root.Data
1aac392120
[NBF]root.Data
1aac392121
[NBF]root.Data
1aac392122
[NBF]root.Data
1aac39213
[NBF]root.Data
1aac39214
[NBF]root.Data
1aac39215
[NBF]root.Data
1aac39216
[NBF]root.Data
1aac39217
[NBF]root.Data
1aac39218
[NBF]root.Data
1aac39219
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Module Name
xy9PC3ocp
Full Name
xy9PC3ocp
EntryPoint
System.Void Xrc3a.Kjw9g1gR/eEj17jDoG6.Wen05kQyM3::aTa7jz5()
Scope Name
xy9PC3ocp
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xy9PC3ocp
Assembly Version
15.27.40.62
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Info
PE Detect: PeReader OK (file layout)
Total Strings
0
Main Method
System.Void Xrc3a.Kjw9g1gR/eEj17jDoG6.Wen05kQyM3::aTa7jz5()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void Xrc3a.Kjw9g1gR::.ctor()
stloc.0 <null>
ret <null>
ldtoken System.Void Xrc3a.Kjw9g1gR/eEj17jDoG6.Wen05kQyM3::aTa7jz5()
pop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙