Malicious
Malicious

735cda5521fe8b13168a40da6bbe2036

PE Executable
MD5: 735cda5521fe8b13168a40da6bbe2036
Size: 1.87 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 735cda5521fe8b13168a40da6bbe2036
Sha1 e35c104f51aafd4e8a6c8605bc0200d35679a41c
Sha256 a70a66a4530d9913f65f5d40945e03a2441ac077c62edc1b4e3f4343555c6943
Sha384 af854ef39c4bf707321272e9da8168a924a35d0e4245bee60b433290dca2104985bfe4b8a0ae672b1fddc4350531f3c4
Sha512 2b6d0e6d0218036f7b6c9269d342d9b9167c796848d41344325732871b6b9e3bf539d24298f1741ec9f45a0774ace68b4441031afb20c719847b65e5c02cffa2
SSDeep 24576:nz7eGUgn/BFIqVHEvmOg+b3JNNAsjbjoEat5Oz4ZOotKTTnmyxdx1JsnjS/rlD:z1kljCqbMpT4OmUnjS/rl
TLSH E585AD017E44CE11F0195333C2EF458897B0A9517AA6E72B7DBA37AE64123A37C0D9DB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
Dd0Sx2UxBstr7kwoKd.T7IFRFJpiIo0lggtEr
ShU4gR4Ao2tNE0t34I.BJT90do3q7yJOobyOg
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Gn1Upe
Full Name
Gn1Upe
EntryPoint
System.Void LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::zkKptOGQAA()
Scope Name
Gn1Upe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EYMjfYldPW6LpLm9fgIw
Assembly Version
1.1.4.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::zkKptOGQAA()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void qnjO2UWj5y1NXlqeys2.c5MPojWwm2D81m8nZWq::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::MIUpURTtIb
callvirt System.Void TW8sJJdwXMqxSb2050y.oJaaJMd7F48nAkv6THk::oUA2eNUfZU()
nop <null>
ret <null>
Module Name
Gn1Upe
Full Name
Gn1Upe
EntryPoint
System.Void LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::zkKptOGQAA()
Scope Name
Gn1Upe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EYMjfYldPW6LpLm9fgIw
Assembly Version
1.1.4.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::zkKptOGQAA()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void qnjO2UWj5y1NXlqeys2.c5MPojWwm2D81m8nZWq::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::MIUpURTtIb
callvirt System.Void TW8sJJdwXMqxSb2050y.oJaaJMd7F48nAkv6THk::oUA2eNUfZU()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
Dd0Sx2UxBstr7kwoKd.T7IFRFJpiIo0lggtEr
ShU4gR4Ao2tNE0t34I.BJT90do3q7yJOobyOg
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙