Malicious
PE Executable
MD5: 618eb6e17478a6c5b6780aec0697e9b1
Size: 841.22 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 618eb6e17478a6c5b6780aec0697e9b1 |
| Sha1 | 5266d46a51eebf58091a098a17022864a01017a6 |
| Sha256 | 5f8849d726446a436c7d56709246a2981039840a8222b362ff6ad3c55df2f878 |
| Sha384 | 88fd93dc879a1ba0be549f43d0618892a65a07c988d14af55dd26b35828ac0c8fa84903ec1bd49e76e25bbb07ea3b6d6 |
| Sha512 | a49309ad6dc41aa255c60c12c4a0e2a455b3aa1c3df0edf23741ddd330e2a6fb81c666f76f7fc6f57eda923c19a78c33767c7eaad7c9496df1f4f6775db0ac06 |
| SSDeep | 12288:cWncFiej+YdLG3Tum07xl8mME70gJ4LGX03TPpqc3eVDXaAvMQ:chTaYg3KfX8mv0e4LGabpheVDdUQ |
| TLSH | 3405AE1B36624F50C2894BB3C1AB950083A7A687B6E3F30FB18513A75D437EEDD46693 |
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
Path
pe:exe>bin
Shape
pe:exe>bin
malicious
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | Eqieelc.exe |
| Full Name | Eqieelc.exe |
| EntryPoint | System.Void dfoETRUjkYdA608gxZ.M15NHYhZyMAvIacjoG::rmDYl2ZNW() |
| Scope Name | Eqieelc.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Eqieelc |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Total Strings | 41 |
| Main Method | System.Void dfoETRUjkYdA608gxZ.M15NHYhZyMAvIacjoG::rmDYl2ZNW() |
| Main IL Instruction Count | 96 |
| Main IL | |