Malicious
Malicious

5b4676f4e90862c6df944f2fc9d2dc35

Share on LinkedIn
Print
PE Executable
MD5: 5b4676f4e90862c6df944f2fc9d2dc35
Size: 1.17 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 5b4676f4e90862c6df944f2fc9d2dc35
Sha1 60a35cd5ae608ca9d46f6dddcb001057bd8090ff
Sha256 90c024fb14d2fdbec018e739e266535a4f6736f042140c98c1cf58e988c0aa5c
Sha384 58b6161f7a16cca96de56f1f71a1eaf4724170140fa467e16598cc5430c6a3fae00353603a5e778884912e400df1800d
Sha512 c73538c3750e5a4a6ac1f096fd80e3eccc8c9bf83bfb96facf9fdfd194569b3c6390fcc69e33f1a69e5b2e0e5110a601f50991eb81a45bae25e36b92daf6efd0
SSDeep 24576:xkZIsmED6d++UOb9fi6UICWHWsG21v6nXo0k1NAEqQCBEw9r:xAI3bsOb9qDI1WsG21vMo0YPe
TLSH 7F45BF5C3102F6AFC8579573CA649DF4A6226CA7C347D39350A33DEA7E3C5A69E040E2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
InkWell.Properties.Resources.resources
UDP
[NBF]root.Data
hTNE
[NBF]root.Data
[NBF]root.Data-preview.png
QIAK.g.resources
hZn.bez.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Module Name
QIAK.exe
Full Name
QIAK.exe
EntryPoint
System.Void VN.r0::Cx()
Scope Name
QIAK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QIAK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void VN.r0::Cx()
Main IL Instruction Count
56
Main IL
br IL_0092: nop
ldc.i4 1151649593
ldc.i4 1705219784
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.s 11
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br IL_00D8: br.s IL_006A
ret <null>
ldloc.0 <null>
ldc.i4 -482035116
mul <null>
ldc.i4 556818065
xor <null>
br.s IL_000A: ldc.i4 1705219784
ldloc.0 <null>
ldc.i4 -341362568
mul <null>
ldc.i4 2089477516
xor <null>
br.s IL_000A: ldc.i4 1705219784
nop <null>
ldc.i4 184160675
br.s IL_000A: ldc.i4 1705219784
ldc.i4.0 <null>
call System.Void VN.r0::‭‏‏‍‎‫‬​​‌‎‪‌‬​‬‬‌‪‬‎‏‍‍‌‮‎‌‮(System.Boolean)
ldloc.0 <null>
ldc.i4 -1980562144
mul <null>
ldc.i4 1213510299
xor <null>
br.s IL_000A: ldc.i4 1705219784
nop <null>
ldc.i4 1597663985
br IL_000A: ldc.i4 1705219784
nop <null>
call System.Void VN.r0::‫‎‪‪‭‍‪​‫‎‫‌‬‭‏​​‎‎‭‪‬‮()
ldc.i4 1151649593
br IL_000A: ldc.i4 1705219784
nop <null>
newobj System.Void Qc.Oa::.ctor()
call System.Void VN.r0::‬‎‏‌‏‍​‍‏‌‌‮‍‏‪‍‭​‏‏‮‍‪‭‌‮(System.Windows.Forms.Form)
ldc.i4 815759814
br IL_000A: ldc.i4 1705219784
call System.Void IGY.cGK::j9u()
ldc.i4 737056576
br IL_000A: ldc.i4 1705219784
ldloc.0 <null>
ldc.i4 1086309852
mul <null>
ldc.i4 -2051977672
xor <null>
br IL_000A: ldc.i4 1705219784
br.s IL_006A: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
QIAK.exe
Full Name
QIAK.exe
EntryPoint
System.Void VN.r0::Cx()
Scope Name
QIAK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
QIAK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
2
Main Method
System.Void VN.r0::Cx()
Main IL Instruction Count
56
Main IL
br IL_0092: nop
ldc.i4 1151649593
ldc.i4 1705219784
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.s 11
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br IL_00D8: br.s IL_006A
ret <null>
ldloc.0 <null>
ldc.i4 -482035116
mul <null>
ldc.i4 556818065
xor <null>
br.s IL_000A: ldc.i4 1705219784
ldloc.0 <null>
ldc.i4 -341362568
mul <null>
ldc.i4 2089477516
xor <null>
br.s IL_000A: ldc.i4 1705219784
nop <null>
ldc.i4 184160675
br.s IL_000A: ldc.i4 1705219784
ldc.i4.0 <null>
call System.Void VN.r0::‭‏‏‍‎‫‬​​‌‎‪‌‬​‬‬‌‪‬‎‏‍‍‌‮‎‌‮(System.Boolean)
ldloc.0 <null>
ldc.i4 -1980562144
mul <null>
ldc.i4 1213510299
xor <null>
br.s IL_000A: ldc.i4 1705219784
nop <null>
ldc.i4 1597663985
br IL_000A: ldc.i4 1705219784
nop <null>
call System.Void VN.r0::‫‎‪‪‭‍‪​‫‎‫‌‬‭‏​​‎‎‭‪‬‮()
ldc.i4 1151649593
br IL_000A: ldc.i4 1705219784
nop <null>
newobj System.Void Qc.Oa::.ctor()
call System.Void VN.r0::‬‎‏‌‏‍​‍‏‌‌‮‍‏‪‍‭​‏‏‮‍‪‭‌‮(System.Windows.Forms.Form)
ldc.i4 815759814
br IL_000A: ldc.i4 1705219784
call System.Void IGY.cGK::j9u()
ldc.i4 737056576
br IL_000A: ldc.i4 1705219784
ldloc.0 <null>
ldc.i4 1086309852
mul <null>
ldc.i4 -2051977672
xor <null>
br IL_000A: ldc.i4 1705219784
br.s IL_006A: nop
An error has occurred. This application may no longer respond until reloaded. Reload 🗙