Malicious
Malicious

5a1bb5d7f55f40596c1335a7728277c0

Share on LinkedIn
Print
PE Executable
MD5: 5a1bb5d7f55f40596c1335a7728277c0
Size: 752.64 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 5a1bb5d7f55f40596c1335a7728277c0
Sha1 02975ba8659e0843913111fcf9cce8c47bf728a5
Sha256 4e4e32f6259b82e6b932ab81172c22560ec2ac46e85543d4851637a63eaace3e
Sha384 e8d170541dd1a3aa3352e64d498b0cca84750b81d180f25a4d3331404f39e9cbf6d554f468ed380128bde90488c86bb7
Sha512 84fb164647ef0c12e95cafa60740676d19f51fbfeb7f6a92cb4289ab06685c13e6a6fc9c4792417d7abdfb95ee45eceb73f460ec0526811391529b0a7d472817
SSDeep 12288:b70cbVq5a5HDq2jimC/LwRe62NtljwBj7VSuzlXxC:30cZMKjnOmQsRx2N/MF7cWXE
TLSH CEF48C3283E95FD5C35D0B37B461C048AF35A5388DABFB7235226278605F34AB66ED18
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
costura.costura.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
costura.protobuf-net.dll.compressed
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
              
1ee89d09774f44849be08a0027102b9f
IfGE6NpBG4IOAxEGb0.OZw77MRI4skWWMXOgu
Hbguhpjezkwzwfpdgb.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Hbguhpjezkwzwfpdgb.Properties.Resources.resources
Rwklucoriyywaxsiv
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:dll>pe:dll>pe:rsrc>bin
Shape pe:dll>pe:dll>pe:rsrc>bin
malicious 4 nodes
Path pe:dll>pe:rsrc>bin
Shape pe:dll>pe:rsrc>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Hbguhpjezkwzwfpdgb.dll
Full Name
Hbguhpjezkwzwfpdgb.dll
Scope Name
Hbguhpjezkwzwfpdgb.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Hbguhpjezkwzwfpdgb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
192
Main Method
Not found or no body
Module Name
Hbguhpjezkwzwfpdgb.dll
Full Name
Hbguhpjezkwzwfpdgb.dll
Scope Name
Hbguhpjezkwzwfpdgb.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Hbguhpjezkwzwfpdgb
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
192
Main Method
Not found or no body
An error has occurred. This application may no longer respond until reloaded. Reload 🗙