Suspicious
Suspect

4fe3017342cbdccfb8bda0bd2a3d876b

PE Executable
MD5: 4fe3017342cbdccfb8bda0bd2a3d876b
Size: 1.44 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 4fe3017342cbdccfb8bda0bd2a3d876b
Sha1 9290b7e00ec048fc9d3f71b5d722ed80febc8c69
Sha256 7aac2dac84d9820bfe3073ca5b662e51036d5aea481f9bec297a91dfdc63e6b4
Sha384 1594e8ac5d66b7385391b108a3609225a2ed78ee3c12f4ca3f542b171b4e50664196ff02ba7739c558710d0afc59f27e
Sha512 bb8c3bc97cd6fdcef9df83fd6ae1a6be8a17538be922c91b00266b8f2aedc0662f12351ba3e2bc55f66b5fa77c0467758c3ce5eb512ea18c8f26cee7756a2db0
SSDeep 24576:SLoPW9IDn0SEfjoQjlwKGwvYbXjrxILoPW9IDn0SEfjoQjlwKGwvYbXjrxcE5q:/n0SEfjoWqwvwzn0SEfjoWqwvw7q
TLSH 2065023B9FEA8982F55267BE50870401CB3616753727B36B334BB1760C50B9EEC2A5E4
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Guna.dll
Guna.dll-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Joiner.exe
Full Name
Joiner.exe
EntryPoint
System.Void StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::xYAtYYEfbYfTaVJsDDpvlxfd(System.String[])
Scope Name
Joiner.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Joiner
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
252
Main Method
System.Void StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::xYAtYYEfbYfTaVJsDDpvlxfd(System.String[])
Main IL Instruction Count
154
Main IL
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::scGcGmumjJQCxcpeQEIjZh()
stloc V_8
br IL_00E7: br IL_000E
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::jjxYmwyEGnqUHJruPn()
ceq <null>
brfalse.s IL_002B: nop
ldloc V_1
brfalse.s IL_0083: call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::rvftWufHFwbEMKn()
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::zyMyvsotOObfNKAWsINHql()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::JPHIiUYJsvm()
ceq <null>
brfalse.s IL_0056: nop
nop <null>
ldsfld System.String StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::YCpGeadYzyeHwdXdq
call System.String bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::dXlBgxCjpfHcJHmzlBfx()
call System.Boolean System.String::op_Equality(System.String,System.String)
stloc V_1
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::tCinjGYpEijbcX()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::GHhKnBPeHfzaiYYqPpUjUDNwq()
ceq <null>
brfalse.s IL_0073: nop
nop <null>
call System.Void bcEhAiMlrggibNZM.yZcEywJvQAwlBdxSWMMt::bkPwAJiCFVkiqBPavjcYyJrau()
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::ulwXAgjmteUVJMeXbIk()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::qQgrUmInfDtkUJHeije()
ceq <null>
brfalse.s IL_0096: nop
nop <null>
nop <null>
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::rvftWufHFwbEMKn()
call System.Void System.Threading.Thread::Sleep(System.Int32)
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::EEDOXwHqlkAAFApseRo()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::lmVZHBhiboYKVdZdfPvuooIl()
ceq <null>
brfalse.s IL_00BF: nop
nop <null>
ldsfld System.String StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::aBMKNfJrVBOwhoJIlaDHCvfV
call System.String bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::eCFHjauVstSjeHWOYOxMqebb()
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_0109: call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::waWpXAAoRBffo()
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::MPVuGwdjfcycb()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::OdockGuBIZfPZLZDzaevWKZ()
ceq <null>
brfalse.s IL_00D7: nop
nop <null>
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::mwpzyeXmxWjjBCrUSK()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::vPqWSJbdXygV()
ceq <null>
brfalse.s IL_00E7: br IL_000E
br.s IL_00EC: call System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
br IL_000E: nop
call System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
newobj System.Void System.Security.Principal.WindowsPrincipal::.ctor(System.Security.Principal.WindowsIdentity)
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::ENqnRuCdBsS()
callvirt System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::cqBxjJdLDd()
ceq <null>
br.s IL_010E: stloc V_2
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::waWpXAAoRBffo()
stloc V_2
ldloc V_2
brfalse.s IL_018F: ldsfld System.String StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::tOgVJukKAsWHYBzFeO
nop <null>
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::EDXIdtWYTqTZg()
stloc V_3
br.s IL_0179: ldloc V_3
nop <null>
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
callvirt System.String System.Reflection.Assembly::get_Location()
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor(System.String)
stloc V_4
ldloc V_4
call System.String bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::pDJAaCtMuEfcBEABwLNleF()
call System.String StCqpFDXTQsdKTMQhXv.BKqmrtZNnYNGIaswLGujSfKJp::VAgwpZKtzJuJayWYubE(System.String)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Verb(System.String)
nop <null>
nop <null>
ldloc V_4
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo)
pop <null>
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::DZjpXHgWxUL()
call System.Void System.Environment::Exit(System.Int32)
nop <null>
nop <null>
leave.s IL_016A: nop
pop <null>
nop <null>
nop <null>
leave.s IL_016A: nop
nop <null>
ldloc V_3
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::OsfEmSrJTcAsSXRtHMvJjxFar()
add <null>
stloc V_3
ldloc V_3
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::WEOhiIpFmIRHbT()
clt <null>
stloc V_5
ldloc V_5
brtrue.s IL_0124: nop
nop <null>
ldsfld System.String StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::tOgVJukKAsWHYBzFeO
call System.String StCqpFDXTQsdKTMQhXv.BKqmrtZNnYNGIaswLGujSfKJp::VAgwpZKtzJuJayWYubE(System.String)
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::wlaYrXzqmOlZCPQnENZvn()
newarr System.Char
dup <null>
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::lusCMlIcAkbXmMeCApWObTwi()
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::pWVMuCXzBzgfoKOhJNAxed()
stelem.i2 <null>
callvirt System.String[] System.String::Split(System.Char[])
stloc V_0
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::ICMjZYTSyKO()
stloc V_6
br.s IL_01E2: ldloc V_6
nop <null>
ldloc V_0
ldloc V_6
ldelem.ref <null>
call System.Void StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::AWFawKGuYfCNcZQvnTXhJ(System.String)
nop <null>
nop <null>
ldloc V_6
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::OmQGhEXkMyWLfHhRF()
add <null>
stloc V_6
ldloc V_6
ldloc V_0
ldlen <null>
conv.i4 <null>
clt <null>
stloc V_7
ldloc V_7
brtrue.s IL_01C3: nop
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Guna.dll
Guna.dll-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙