Suspicious
Suspect

6b058559a54275746bfc645d5c5214d0

PE Executable
MD5: 6b058559a54275746bfc645d5c5214d0
Size: 1.24 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 6b058559a54275746bfc645d5c5214d0
Sha1 46cb66556e0b2b44df79d815fc27cd65859d759d
Sha256 d2a4ad1db761a3776160317ba0325d100e65d2baea62d52effee899ab5d355a8
Sha384 2b4751886c6b870ab73c754e26291eae1be584d22bcc0ce6449f91d29e0ae3efdccfd381b52ea2cbe8fc6dc74755d3b7
Sha512 ae99d8274dc0479b3d94f8a5ebb58ad0b30cb56f005269d3ad52b61e4dbbe6173d01b53a13119f191176df01e60e821dcadde5240242aea6a80e4af5dd338ac2
SSDeep 24576:4cUAtPa6ObJ+SAmkqkX7YhQzi5IO7WL4iAJR:HXPalESAmyWQzmHWL
TLSH 0E45F02112D99F59F5BF97348875501887F3BC46DF31D7EE3E8C18EA3A22A818661723
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
qWp8f3Fm.g.resources
qWp8f3Fm.Resources.resources
ef157e9e3da0b9.Resources.resources
855ac7e50
[NBF]root.Data
855ac7e51
[NBF]root.Data
855ac7e510
[NBF]root.Data
855ac7e511
[NBF]root.Data
855ac7e512
[NBF]root.Data
855ac7e513
[NBF]root.Data
855ac7e514
[NBF]root.Data
855ac7e515
[NBF]root.Data
855ac7e516
[NBF]root.Data
855ac7e517
[NBF]root.Data
855ac7e518
[NBF]root.Data
855ac7e519
[NBF]root.Data
855ac7e52
[NBF]root.Data
855ac7e520
[NBF]root.Data
855ac7e521
[NBF]root.Data
855ac7e522
[NBF]root.Data
855ac7e523
[NBF]root.Data
855ac7e524
[NBF]root.Data
855ac7e53
[NBF]root.Data
855ac7e54
[NBF]root.Data
855ac7e55
[NBF]root.Data
855ac7e56
[NBF]root.Data
855ac7e57
[NBF]root.Data
855ac7e58
[NBF]root.Data
855ac7e59
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
qWp8f3Fm
Full Name
qWp8f3Fm
EntryPoint
System.Void qWp8f3Fm.Fe9mk::Ctp4s7aPiE6rT()
Scope Name
qWp8f3Fm
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qWp8f3Fm
Assembly Version
8.19.28.283
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
785
Main Method
System.Void qWp8f3Fm.Fe9mk::Ctp4s7aPiE6rT()
Main IL Instruction Count
85
Main IL
nop <null>
nop <null>
newobj System.Void System.Windows.Forms.Form::.ctor()
stloc.0 <null>
ldstr Capnogramat
call System.Boolean qWp8f3Fm.Fe9mk/1deNoQ6yj3gY.0cwRaW4s7_Nwot::zGw8P(System.String)
ldc.i4.0 <null>
ceq <null>
stloc.s V_7
ldloc.s V_7
brfalse.s IL_0020: ldc.r8 25
leave IL_00D4: ret
ldc.r8 25
call System.Double System.Math::Abs(System.Double)
call System.Double System.Math::Round(System.Double)
conv.ovf.i4 <null>
stloc.1 <null>
ldtoken System.Object
call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle)
ldloc.1 <null>
call System.Array System.Array::CreateInstance(System.Type,System.Int32)
castclass System.Object[]
stloc.2 <null>
ldstr /
ldc.i4.2 <null>
newarr System.String
dup <null>
ldc.i4.0 <null>
ldstr resources
stelem.ref <null>
dup <null>
ldc.i4.1 <null>
ldstr 892436.pcx
stelem.ref <null>
call System.String System.String::Join(System.String,System.String[])
stloc.3 <null>
ldloc.2 <null>
ldc.i4.0 <null>
ldloc.3 <null>
stelem.ref <null>
newobj System.Void System.Windows.Forms.Panel::.ctor()
stloc.s V_4
ldloc.3 <null>
call System.Byte[] qWp8f3Fm.dZi58bwAdB::Br3z1_aDE8j(System.String)
stloc.s V_5
ldloc.s V_5
ldnull <null>
ceq <null>
stloc.s V_8
ldloc.s V_8
brfalse.s IL_008C: ldloc.s V_5
leave.s IL_00D4: ret
ldloc.s V_5
call System.Void System.Array::Reverse(System.Array)
nop <null>
ldloc.2 <null>
ldc.i4.2 <null>
ldloc.s V_5
stelem.ref <null>
ldloc.2 <null>
ldc.i4.3 <null>
ldloc.s V_5
call System.Byte[] qWp8f3Fm.Bnz38Tfxt2Kg4j/Rzm03wKtr5qA.Ex3ke2Mn7Ko::mk9Z8iLzGs(System.Byte[])
stelem.ref <null>
ldstr L o a d
stloc.s V_6
ldloc.s V_6
ldloc.2 <null>
ldc.i4.3 <null>
ldelem.ref <null>
call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object)
call System.Object qWp8f3Fm.Fe9mk/cj6Eg0Gm.Gbo1p4Pj::ya1ZsRs8(System.String,System.Object)
pop <null>
leave.s IL_00D3: nop
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.s V_9
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_00D3: nop
nop <null>
ret <null>
Module Name
qWp8f3Fm
Full Name
qWp8f3Fm
EntryPoint
System.Void qWp8f3Fm.Fe9mk::Ctp4s7aPiE6rT()
Scope Name
qWp8f3Fm
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
qWp8f3Fm
Assembly Version
8.19.28.283
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
785
Main Method
System.Void qWp8f3Fm.Fe9mk::Ctp4s7aPiE6rT()
Main IL Instruction Count
85
Main IL
nop <null>
nop <null>
newobj System.Void System.Windows.Forms.Form::.ctor()
stloc.0 <null>
ldstr Capnogramat
call System.Boolean qWp8f3Fm.Fe9mk/1deNoQ6yj3gY.0cwRaW4s7_Nwot::zGw8P(System.String)
ldc.i4.0 <null>
ceq <null>
stloc.s V_7
ldloc.s V_7
brfalse.s IL_0020: ldc.r8 25
leave IL_00D4: ret
ldc.r8 25
call System.Double System.Math::Abs(System.Double)
call System.Double System.Math::Round(System.Double)
conv.ovf.i4 <null>
stloc.1 <null>
ldtoken System.Object
call System.Type System.Type::GetTypeFromHandle(System.RuntimeTypeHandle)
ldloc.1 <null>
call System.Array System.Array::CreateInstance(System.Type,System.Int32)
castclass System.Object[]
stloc.2 <null>
ldstr /
ldc.i4.2 <null>
newarr System.String
dup <null>
ldc.i4.0 <null>
ldstr resources
stelem.ref <null>
dup <null>
ldc.i4.1 <null>
ldstr 892436.pcx
stelem.ref <null>
call System.String System.String::Join(System.String,System.String[])
stloc.3 <null>
ldloc.2 <null>
ldc.i4.0 <null>
ldloc.3 <null>
stelem.ref <null>
newobj System.Void System.Windows.Forms.Panel::.ctor()
stloc.s V_4
ldloc.3 <null>
call System.Byte[] qWp8f3Fm.dZi58bwAdB::Br3z1_aDE8j(System.String)
stloc.s V_5
ldloc.s V_5
ldnull <null>
ceq <null>
stloc.s V_8
ldloc.s V_8
brfalse.s IL_008C: ldloc.s V_5
leave.s IL_00D4: ret
ldloc.s V_5
call System.Void System.Array::Reverse(System.Array)
nop <null>
ldloc.2 <null>
ldc.i4.2 <null>
ldloc.s V_5
stelem.ref <null>
ldloc.2 <null>
ldc.i4.3 <null>
ldloc.s V_5
call System.Byte[] qWp8f3Fm.Bnz38Tfxt2Kg4j/Rzm03wKtr5qA.Ex3ke2Mn7Ko::mk9Z8iLzGs(System.Byte[])
stelem.ref <null>
ldstr L o a d
stloc.s V_6
ldloc.s V_6
ldloc.2 <null>
ldc.i4.3 <null>
ldelem.ref <null>
call System.Object System.Runtime.CompilerServices.RuntimeHelpers::GetObjectValue(System.Object)
call System.Object qWp8f3Fm.Fe9mk/cj6Eg0Gm.Gbo1p4Pj::ya1ZsRs8(System.String,System.Object)
pop <null>
leave.s IL_00D3: nop
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.s V_9
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_00D3: nop
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
qWp8f3Fm.g.resources
qWp8f3Fm.Resources.resources
ef157e9e3da0b9.Resources.resources
855ac7e50
[NBF]root.Data
855ac7e51
[NBF]root.Data
855ac7e510
[NBF]root.Data
855ac7e511
[NBF]root.Data
855ac7e512
[NBF]root.Data
855ac7e513
[NBF]root.Data
855ac7e514
[NBF]root.Data
855ac7e515
[NBF]root.Data
855ac7e516
[NBF]root.Data
855ac7e517
[NBF]root.Data
855ac7e518
[NBF]root.Data
855ac7e519
[NBF]root.Data
855ac7e52
[NBF]root.Data
855ac7e520
[NBF]root.Data
855ac7e521
[NBF]root.Data
855ac7e522
[NBF]root.Data
855ac7e523
[NBF]root.Data
855ac7e524
[NBF]root.Data
855ac7e53
[NBF]root.Data
855ac7e54
[NBF]root.Data
855ac7e55
[NBF]root.Data
855ac7e56
[NBF]root.Data
855ac7e57
[NBF]root.Data
855ac7e58
[NBF]root.Data
855ac7e59
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙