Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 7192731baec2a32f438a994c15f8ce8b
Sha1 9175fbce719442bbd2768a1e67c4fb94a6f3c367
Sha256 b24fefefe8a95d6a765caff9b0ae40ed480dfdbfe2e5a46848b1a9d895ec83e3
Sha384 692befeb6eff36a31d3b3bf0e593c1f8d0fe6029d235a9a20ed26e7e1e50e57e502636c3d569373f6f502ff3c782add6
Sha512 2033f9a945a03bbece3a3114e6104790d2b5900a7fd1cee1d644a04b9d1c72052b23684ac55914086682a190d7783a6b3c9af9928abfa9b49a063d91ca115a39
SSDeep 24576:uf2UxAPqGcv/+Duyx4tVItPAO8I8vo7Ve752lkO8/MshOXzBuqLG2rZkRJxT:u3qPRcvEAGtE1A71cYBM2t
TLSH B4A5120C27E85B56EC7D8B3A84345AA493F0BC42A72ADB5E7E4C31ED0E357C0A946753
PeID
.NET executableMEW 11 SE 1.2Microsoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
ID:0-preview.png
ID:0033
ID:0
ID:0034
ID:0
ID:0035
ID:0
ID:0036
ID:0
ID:0037
ID:0
ID:0038
ID:0
ID:0039
ID:0
ID:003A
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Genitalk.klaoxao.tiff
3Kwkw.Resources.resources
31da911b7fd69a.Resources.resources
606b6d1b0
[NBF]root.Data
606b6d1b1
[NBF]root.Data
606b6d1b10
[NBF]root.Data
606b6d1b11
[NBF]root.Data
606b6d1b12
[NBF]root.Data
606b6d1b13
[NBF]root.Data
606b6d1b14
[NBF]root.Data
606b6d1b15
[NBF]root.Data
606b6d1b16
[NBF]root.Data
606b6d1b17
[NBF]root.Data
606b6d1b18
[NBF]root.Data
606b6d1b19
[NBF]root.Data
606b6d1b2
[NBF]root.Data
606b6d1b20
[NBF]root.Data
606b6d1b21
[NBF]root.Data
606b6d1b22
[NBF]root.Data
606b6d1b23
[NBF]root.Data
606b6d1b24
[NBF]root.Data
606b6d1b25
[NBF]root.Data
606b6d1b26
[NBF]root.Data
606b6d1b27
[NBF]root.Data
606b6d1b28
[NBF]root.Data
606b6d1b29
[NBF]root.Data
606b6d1b3
[NBF]root.Data
606b6d1b30
[NBF]root.Data
606b6d1b31
[NBF]root.Data
606b6d1b32
[NBF]root.Data
606b6d1b33
[NBF]root.Data
606b6d1b34
[NBF]root.Data
606b6d1b35
[NBF]root.Data
606b6d1b36
[NBF]root.Data
606b6d1b37
[NBF]root.Data
606b6d1b38
[NBF]root.Data
606b6d1b39
[NBF]root.Data
606b6d1b4
[NBF]root.Data
606b6d1b40
[NBF]root.Data
606b6d1b41
[NBF]root.Data
606b6d1b42
[NBF]root.Data
606b6d1b43
[NBF]root.Data
606b6d1b44
[NBF]root.Data
606b6d1b45
[NBF]root.Data
606b6d1b46
[NBF]root.Data
606b6d1b47
[NBF]root.Data
606b6d1b48
[NBF]root.Data
606b6d1b49
[NBF]root.Data
606b6d1b5
[NBF]root.Data
606b6d1b50
[NBF]root.Data
606b6d1b51
[NBF]root.Data
606b6d1b52
[NBF]root.Data
606b6d1b53
[NBF]root.Data
606b6d1b54
[NBF]root.Data
606b6d1b55
[NBF]root.Data
606b6d1b56
[NBF]root.Data
606b6d1b57
[NBF]root.Data
606b6d1b58
[NBF]root.Data
606b6d1b6
[NBF]root.Data
606b6d1b7
[NBF]root.Data
606b6d1b8
[NBF]root.Data
606b6d1b9
[NBF]root.Data
.Net Reflective Loader
Malicious
Overlay_ddd3db78.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
ObjectRequester.ScopeObject
ScheduledObject.ObjectParser
DecryptorCompressor.ControllableObject
AuditorMap.LocalObject
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path pe:exe>pe:dll>pe:rsrc>bin
Shape pe:exe>pe:dll>pe:rsrc>bin
malicious 4 nodes
Path pe:exe>pe:dll>bin
Shape pe:exe>pe:dll>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
3Kwkw
Full Name
3Kwkw
EntryPoint
System.Void 3Kwkw.2jpLcrR::bc9CkDs1()
Scope Name
3Kwkw
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
3Kwkw
Assembly Version
9.6.29.151
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1031
Main Method
System.Void 3Kwkw.2jpLcrR::bc9CkDs1()
Main IL Instruction Count
37
Main IL
nop <null>
ldc.i4.s 25
ldc.i4.6 <null>
ldc.i4 2026
call System.DateTime Microsoft.VisualBasic.DateAndTime::DateSerial(System.Int32,System.Int32,System.Int32)
stloc.0 <null>
ldloca.s V_1
initobj Microsoft.VisualBasic.FirstDayOfWeek
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Boolean 3Kwkw.2jpLcrR::Tt8prkJ()
ldc.i4.0 <null>
ceq <null>
stloc.2 <null>
ldloc.2 <null>
brfalse.s IL_0038: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
nop <null>
nop <null>
call System.Void 3Kwkw.2jpLcrR::Pix06()
nop <null>
ldstr requiredResources(1)
ldstr requiredResources(3)
call System.Void 3Kwkw.2jpLcrR::6Xqdi0z(System.String,System.String)
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
newobj System.Void 3Kwkw.2jpLcrR::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Module Name
3Kwkw
Full Name
3Kwkw
EntryPoint
System.Void 3Kwkw.2jpLcrR::bc9CkDs1()
Scope Name
3Kwkw
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
3Kwkw
Assembly Version
9.6.29.151
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1031
Main Method
System.Void 3Kwkw.2jpLcrR::bc9CkDs1()
Main IL Instruction Count
37
Main IL
nop <null>
ldc.i4.s 25
ldc.i4.6 <null>
ldc.i4 2026
call System.DateTime Microsoft.VisualBasic.DateAndTime::DateSerial(System.Int32,System.Int32,System.Int32)
stloc.0 <null>
ldloca.s V_1
initobj Microsoft.VisualBasic.FirstDayOfWeek
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
call System.Boolean 3Kwkw.2jpLcrR::Tt8prkJ()
ldc.i4.0 <null>
ceq <null>
stloc.2 <null>
ldloc.2 <null>
brfalse.s IL_0038: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
nop <null>
nop <null>
call System.Void 3Kwkw.2jpLcrR::Pix06()
nop <null>
ldstr requiredResources(1)
ldstr requiredResources(3)
call System.Void 3Kwkw.2jpLcrR::6Xqdi0z(System.String,System.String)
nop <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
newobj System.Void 3Kwkw.2jpLcrR::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
ID:0-preview.png
ID:0033
ID:0
ID:0034
ID:0
ID:0035
ID:0
ID:0036
ID:0
ID:0037
ID:0
ID:0038
ID:0
ID:0039
ID:0
ID:003A
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Genitalk.klaoxao.tiff
3Kwkw.Resources.resources
31da911b7fd69a.Resources.resources
606b6d1b0
[NBF]root.Data
606b6d1b1
[NBF]root.Data
606b6d1b10
[NBF]root.Data
606b6d1b11
[NBF]root.Data
606b6d1b12
[NBF]root.Data
606b6d1b13
[NBF]root.Data
606b6d1b14
[NBF]root.Data
606b6d1b15
[NBF]root.Data
606b6d1b16
[NBF]root.Data
606b6d1b17
[NBF]root.Data
606b6d1b18
[NBF]root.Data
606b6d1b19
[NBF]root.Data
606b6d1b2
[NBF]root.Data
606b6d1b20
[NBF]root.Data
606b6d1b21
[NBF]root.Data
606b6d1b22
[NBF]root.Data
606b6d1b23
[NBF]root.Data
606b6d1b24
[NBF]root.Data
606b6d1b25
[NBF]root.Data
606b6d1b26
[NBF]root.Data
606b6d1b27
[NBF]root.Data
606b6d1b28
[NBF]root.Data
606b6d1b29
[NBF]root.Data
606b6d1b3
[NBF]root.Data
606b6d1b30
[NBF]root.Data
606b6d1b31
[NBF]root.Data
606b6d1b32
[NBF]root.Data
606b6d1b33
[NBF]root.Data
606b6d1b34
[NBF]root.Data
606b6d1b35
[NBF]root.Data
606b6d1b36
[NBF]root.Data
606b6d1b37
[NBF]root.Data
606b6d1b38
[NBF]root.Data
606b6d1b39
[NBF]root.Data
606b6d1b4
[NBF]root.Data
606b6d1b40
[NBF]root.Data
606b6d1b41
[NBF]root.Data
606b6d1b42
[NBF]root.Data
606b6d1b43
[NBF]root.Data
606b6d1b44
[NBF]root.Data
606b6d1b45
[NBF]root.Data
606b6d1b46
[NBF]root.Data
606b6d1b47
[NBF]root.Data
606b6d1b48
[NBF]root.Data
606b6d1b49
[NBF]root.Data
606b6d1b5
[NBF]root.Data
606b6d1b50
[NBF]root.Data
606b6d1b51
[NBF]root.Data
606b6d1b52
[NBF]root.Data
606b6d1b53
[NBF]root.Data
606b6d1b54
[NBF]root.Data
606b6d1b55
[NBF]root.Data
606b6d1b56
[NBF]root.Data
606b6d1b57
[NBF]root.Data
606b6d1b58
[NBF]root.Data
606b6d1b6
[NBF]root.Data
606b6d1b7
[NBF]root.Data
606b6d1b8
[NBF]root.Data
606b6d1b9
[NBF]root.Data
.Net Reflective Loader
Malicious
Overlay_ddd3db78.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
ObjectRequester.ScopeObject
ScheduledObject.ObjectParser
DecryptorCompressor.ControllableObject
AuditorMap.LocalObject
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙