Suspicious
Suspect

4e2b713333af326c9a2bf8a35921b67b

PE Executable
MD5: 4e2b713333af326c9a2bf8a35921b67b
Size: 750.59 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 4e2b713333af326c9a2bf8a35921b67b
Sha1 2e2e91c941f136eecb4ebfcd3e279aabca6a095b
Sha256 3feb5b6941b766f05d36adc9e2de9a3f631e9722d4bf083c2de4c0d5ff5208e2
Sha384 6db28dc9707184182110555f53001b8aaadabb3b924c7e726147b3302eaeadadf889728caa5d073e2d117c64eaebb02b
Sha512 9aa2ac80ac2527f312e287d3f84d6d337b16952da23f0ab8b37028cd43d464317c4013ea33a770248928a5d7bb93d82abb890affdb9f262725081a079f82e88c
SSDeep 12288:T9WXbMskTPr6NcUkqjVnl36ud0zR/6CtQ9PUHIG8DXjAGq2amJYeQab+3NUW6:T9WXMr6NcUkqjVnlqud+/2P+ATAS/JYA
TLSH 44F4DF58B3F85A00F1FF5BB194B59D51AB35B513A962D71E11C080D80EB2B918F8AF3B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Stub.Properties.Resources.resources
costura.costura.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.costura.pdb.compressed
costura.newtonsoft.json.dll.compressed
[Authenticode]_220cad77.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.icsharpcode.sharpziplib.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.icsharpcode.sharpziplib.pdb.compressed
costura.icsharpcode.sharpziplib.pdb
costura.system.diagnostics.diagnosticsource.dll.compressed
[Authenticode]_50c89911.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.metadata
Resources.ProductVersion
Resources.CompanyName
Resources.ProductName
Resources.LegalCopyright
Resources.FileDescription
Resources.OriginalFilename
Resources.InternalName
Resources.BuildVersion
Resources.PrivateBuild
Resources.SYS_SVC_START
Resources.SYS_SVC_STOP
Resources.SYS_SVC_PAUSE
Resources.SYS_SVC_RESUME
Resources.SYS_NET_CONNECT
Resources.SYS_UPDATE_CHECK
Resources.SYS_SEC_SCAN
Resources.AppIcon
Resources.AppIcon-preview.png
Resources.Manifest
STICH beta

No STICH Path has been generated for this analysis yet.

5 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 4img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ?
Module Name
stub.exe
Full Name
stub.exe
EntryPoint
System.Void Stub.Program::<Main>()
Scope Name
stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
stub
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
3177
Main Method
System.Void Stub.Program::<Main>()
Main IL Instruction Count
6
Main IL
call System.Threading.Tasks.Task Stub.Program::Main()
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Module Name
stub.exe
Full Name
stub.exe
EntryPoint
System.Void Stub.Program::<Main>()
Scope Name
stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
stub
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
3177
Main Method
System.Void Stub.Program::<Main>()
Main IL Instruction Count
6
Main IL
call System.Threading.Tasks.Task Stub.Program::Main()
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Stub.Properties.Resources.resources
costura.costura.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.costura.pdb.compressed
costura.newtonsoft.json.dll.compressed
[Authenticode]_220cad77.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.icsharpcode.sharpziplib.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.icsharpcode.sharpziplib.pdb.compressed
costura.icsharpcode.sharpziplib.pdb
costura.system.diagnostics.diagnosticsource.dll.compressed
[Authenticode]_50c89911.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.metadata
Resources.ProductVersion
Resources.CompanyName
Resources.ProductName
Resources.LegalCopyright
Resources.FileDescription
Resources.OriginalFilename
Resources.InternalName
Resources.BuildVersion
Resources.PrivateBuild
Resources.SYS_SVC_START
Resources.SYS_SVC_STOP
Resources.SYS_SVC_PAUSE
Resources.SYS_SVC_RESUME
Resources.SYS_NET_CONNECT
Resources.SYS_UPDATE_CHECK
Resources.SYS_SEC_SCAN
Resources.AppIcon
Resources.AppIcon-preview.png
Resources.Manifest
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙