Suspicious
Suspect

5ab37eb5cab63897842d1fcfbdbb5ab5

PE Executable
MD5: 5ab37eb5cab63897842d1fcfbdbb5ab5
Size: 173.06 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 5ab37eb5cab63897842d1fcfbdbb5ab5
Sha1 eb2f2d548d46e3960ae266d8323fda85b10ff5b6
Sha256 447eca66f65d8a13bcf52f304c8780d007961b820d3bb6c439fb266bfc34e474
Sha384 82838e858fff295526496c989d9c90a9c8009c8864c47272c7cba74335ec2477a9523585c501d5e139db1b4ee79509f2
Sha512 1e1b82c9327af021635de002cd66d779a22e665af0aea934e8a7d49c6123b83842277e48ab4c26af3b5b8eaedc251a8d8b5ef7b05e15d6d575490a65ae89a8e7
SSDeep 3072:gULodAihv4zO7ClmVQOnr9b9qS1LANNekICEtCLezUMaGBCGZOgi:6XsMr9b0S1c2sLM
TLSH C304C5247AE682A9F1F76F71C7D1718A46ADE1332F03675D509203471E23A81ECEB939
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ujeTKxyb7Li7h6F0JeuE
Full Name
ujeTKxyb7Li7h6F0JeuE
EntryPoint
System.Void jPiTnir8k25mYLR1IU78.4OJkfW6yiKfq14dWr6cr::ap27cM77xw2aDsofVTNY()
Scope Name
ujeTKxyb7Li7h6F0JeuE
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
new file
Assembly Version
10.4.5606.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
1262
Main Method
System.Void jPiTnir8k25mYLR1IU78.4OJkfW6yiKfq14dWr6cr::ap27cM77xw2aDsofVTNY()
Main IL Instruction Count
39
Main IL
call System.Boolean ogJAkGBO8gABExfraJhc.m5TUYhPUvQfcSxInr6XG::AflBC9S0YfTf1HKSXobD()
stloc V_0
call System.Boolean jPiTnir8k25mYLR1IU78.4OJkfW6yiKfq14dWr6cr::SnLdqukz2LnPMNd5Gyd0()
stloc V_1
call System.Boolean jPiTnir8k25mYLR1IU78.4OJkfW6yiKfq14dWr6cr::Msq9neUu7u9bifPgC5uk()
stloc V_2
call System.Boolean ogJAkGBO8gABExfraJhc.m5TUYhPUvQfcSxInr6XG::qgTRAXjHprADmbbHkSSp()
stloc V_3
call System.Boolean ogJAkGBO8gABExfraJhc.m5TUYhPUvQfcSxInr6XG::YowQxAKKnp0CuUPTV4Ae()
stloc V_4
call System.Boolean ogJAkGBO8gABExfraJhc.m5TUYhPUvQfcSxInr6XG::pLb7eQsq5C8E6meCkDUz()
stloc V_5
call System.Boolean ogJAkGBO8gABExfraJhc.m5TUYhPUvQfcSxInr6XG::N8UA0xI1VSmPRezMMZbg()
stloc V_6
call System.Boolean jPiTnir8k25mYLR1IU78.4OJkfW6yiKfq14dWr6cr::c666WZdOqIQttLf0xcpL()
stloc V_7
call System.Boolean AFDZdfh6Apj0gjKmEyuJ.rGRufgqBXzEdY1K4mCuw::4A6HMCtUhCbXYD6toJkw()
stloc V_8
ldloc V_0
brfalse IL_00A8: ret
ldloc V_1
brfalse IL_00A8: ret
ldloc V_2
brfalse IL_00A8: ret
ldloc V_3
brfalse IL_00A8: ret
ldloc V_4
brfalse IL_00A8: ret
ldloc V_5
brfalse IL_00A8: ret
ldloc V_6
brfalse IL_00A8: ret
ldloc V_7
brfalse IL_00A8: ret
ldloc V_8
brfalse IL_00A8: ret
call System.Void cgvSjs5kRTqe4IH1CxIT.E3V33t0i0xn5KvyWTuZ6::X1ygKGd3oxNVJ02JU1oq()
ret <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙