Suspicious
Suspect

4fe3017342cbdccfb8bda0bd2a3d876b

Share on LinkedIn
Print
PE Executable
MD5: 4fe3017342cbdccfb8bda0bd2a3d876b
Size: 1.44 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 4fe3017342cbdccfb8bda0bd2a3d876b
Sha1 9290b7e00ec048fc9d3f71b5d722ed80febc8c69
Sha256 7aac2dac84d9820bfe3073ca5b662e51036d5aea481f9bec297a91dfdc63e6b4
Sha384 1594e8ac5d66b7385391b108a3609225a2ed78ee3c12f4ca3f542b171b4e50664196ff02ba7739c558710d0afc59f27e
Sha512 bb8c3bc97cd6fdcef9df83fd6ae1a6be8a17538be922c91b00266b8f2aedc0662f12351ba3e2bc55f66b5fa77c0467758c3ce5eb512ea18c8f26cee7756a2db0
SSDeep 24576:SLoPW9IDn0SEfjoQjlwKGwvYbXjrxILoPW9IDn0SEfjoQjlwKGwvYbXjrxcE5q:/n0SEfjoWqwvwzn0SEfjoWqwvw7q
TLSH 2065023B9FEA8982F55267BE50870401CB3616753727B36B334BB1760C50B9EEC2A5E4
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Guna.dll
Guna.dll-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Joiner.exe
Full Name
Joiner.exe
EntryPoint
System.Void StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::xYAtYYEfbYfTaVJsDDpvlxfd(System.String[])
Scope Name
Joiner.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Joiner
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
252
Main Method
System.Void StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::xYAtYYEfbYfTaVJsDDpvlxfd(System.String[])
Main IL Instruction Count
154
Main IL
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::scGcGmumjJQCxcpeQEIjZh()
stloc V_8
br IL_00E7: br IL_000E
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::jjxYmwyEGnqUHJruPn()
ceq <null>
brfalse.s IL_002B: nop
ldloc V_1
brfalse.s IL_0083: call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::rvftWufHFwbEMKn()
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::zyMyvsotOObfNKAWsINHql()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::JPHIiUYJsvm()
ceq <null>
brfalse.s IL_0056: nop
nop <null>
ldsfld System.String StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::YCpGeadYzyeHwdXdq
call System.String bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::dXlBgxCjpfHcJHmzlBfx()
call System.Boolean System.String::op_Equality(System.String,System.String)
stloc V_1
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::tCinjGYpEijbcX()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::GHhKnBPeHfzaiYYqPpUjUDNwq()
ceq <null>
brfalse.s IL_0073: nop
nop <null>
call System.Void bcEhAiMlrggibNZM.yZcEywJvQAwlBdxSWMMt::bkPwAJiCFVkiqBPavjcYyJrau()
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::ulwXAgjmteUVJMeXbIk()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::qQgrUmInfDtkUJHeije()
ceq <null>
brfalse.s IL_0096: nop
nop <null>
nop <null>
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::rvftWufHFwbEMKn()
call System.Void System.Threading.Thread::Sleep(System.Int32)
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::EEDOXwHqlkAAFApseRo()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::lmVZHBhiboYKVdZdfPvuooIl()
ceq <null>
brfalse.s IL_00BF: nop
nop <null>
ldsfld System.String StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::aBMKNfJrVBOwhoJIlaDHCvfV
call System.String bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::eCFHjauVstSjeHWOYOxMqebb()
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_0109: call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::waWpXAAoRBffo()
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::MPVuGwdjfcycb()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::OdockGuBIZfPZLZDzaevWKZ()
ceq <null>
brfalse.s IL_00D7: nop
nop <null>
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::mwpzyeXmxWjjBCrUSK()
stloc V_8
nop <null>
ldloc V_8
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::vPqWSJbdXygV()
ceq <null>
brfalse.s IL_00E7: br IL_000E
br.s IL_00EC: call System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
br IL_000E: nop
call System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
newobj System.Void System.Security.Principal.WindowsPrincipal::.ctor(System.Security.Principal.WindowsIdentity)
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::ENqnRuCdBsS()
callvirt System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::cqBxjJdLDd()
ceq <null>
br.s IL_010E: stloc V_2
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::waWpXAAoRBffo()
stloc V_2
ldloc V_2
brfalse.s IL_018F: ldsfld System.String StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::tOgVJukKAsWHYBzFeO
nop <null>
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::EDXIdtWYTqTZg()
stloc V_3
br.s IL_0179: ldloc V_3
nop <null>
call System.Reflection.Assembly System.Reflection.Assembly::GetExecutingAssembly()
callvirt System.String System.Reflection.Assembly::get_Location()
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor(System.String)
stloc V_4
ldloc V_4
call System.String bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::pDJAaCtMuEfcBEABwLNleF()
call System.String StCqpFDXTQsdKTMQhXv.BKqmrtZNnYNGIaswLGujSfKJp::VAgwpZKtzJuJayWYubE(System.String)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Verb(System.String)
nop <null>
nop <null>
ldloc V_4
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo)
pop <null>
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::DZjpXHgWxUL()
call System.Void System.Environment::Exit(System.Int32)
nop <null>
nop <null>
leave.s IL_016A: nop
pop <null>
nop <null>
nop <null>
leave.s IL_016A: nop
nop <null>
ldloc V_3
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::OsfEmSrJTcAsSXRtHMvJjxFar()
add <null>
stloc V_3
ldloc V_3
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::WEOhiIpFmIRHbT()
clt <null>
stloc V_5
ldloc V_5
brtrue.s IL_0124: nop
nop <null>
ldsfld System.String StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::tOgVJukKAsWHYBzFeO
call System.String StCqpFDXTQsdKTMQhXv.BKqmrtZNnYNGIaswLGujSfKJp::VAgwpZKtzJuJayWYubE(System.String)
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::wlaYrXzqmOlZCPQnENZvn()
newarr System.Char
dup <null>
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::lusCMlIcAkbXmMeCApWObTwi()
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::pWVMuCXzBzgfoKOhJNAxed()
stelem.i2 <null>
callvirt System.String[] System.String::Split(System.Char[])
stloc V_0
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::ICMjZYTSyKO()
stloc V_6
br.s IL_01E2: ldloc V_6
nop <null>
ldloc V_0
ldloc V_6
ldelem.ref <null>
call System.Void StCqpFDXTQsdKTMQhXv.VXpaUdaOWyoASuwMcDOYZYMjf::AWFawKGuYfCNcZQvnTXhJ(System.String)
nop <null>
nop <null>
ldloc V_6
call System.Int32 bcEhAiMlrggibNZM.ODzPQKgFNGRbbYClIM::OmQGhEXkMyWLfHhRF()
add <null>
stloc V_6
ldloc V_6
ldloc V_0
ldlen <null>
conv.i4 <null>
clt <null>
stloc V_7
ldloc V_7
brtrue.s IL_01C3: nop
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙