Malicious
PE Executable
MD5: 3ef62083dc7fcdcad082954d8675b3de
Size: 245.25 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 3ef62083dc7fcdcad082954d8675b3de |
| Sha1 | dedbc07d033f66fbb74065c82912d646c54a2d5b |
| Sha256 | 4d08acae8180270235f519d9ec24e27e94c32f5c0370edd122bc6dc1f33a8240 |
| Sha384 | 43cfc17ef87a2a41fd26d270c0d250e3a02a8455b07a2bcc4754d5f5d5f638e58d90767ce381437efedbcb9ce3e2ba43 |
| Sha512 | 9f24d3bed8ee68f79dfd308e53e4feb5ec8a35b8d68d6286730e6a658e2a90e5bb5e1df2aa5493239532f7055b2532912b0680680e8e8175b998489f798d0603 |
| SSDeep | 3072:ECliq6CyZVc/2MKc2BLIg0THo9rG8KaG5jnTh/qYufzz:Viq6CyDY2Mk+sq8KaWTd |
| TLSH | FB340F027F88E715E1A93E3782EF6C2453B2B4C71633C60BAF49AF5524516826C7E72D |
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | 8N57q4CivJ |
| Full Name | 8N57q4CivJ |
| EntryPoint | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Scope Name | 8N57q4CivJ |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | f45b853c-c9d3-495e-9acb-d41a4a90029f |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 1093 |
| Main Method | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Main IL Instruction Count | 62 |
| Main IL | |
| Module Name | 8N57q4CivJ |
| Full Name | 8N57q4CivJ |
| EntryPoint | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Scope Name | 8N57q4CivJ |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | f45b853c-c9d3-495e-9acb-d41a4a90029f |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 1093 |
| Main Method | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Main IL Instruction Count | 62 |
| Main IL | |