Malicious
Malicious

735cda5521fe8b13168a40da6bbe2036

Share on LinkedIn
Print
PE Executable
MD5: 735cda5521fe8b13168a40da6bbe2036
Size: 1.87 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 735cda5521fe8b13168a40da6bbe2036
Sha1 e35c104f51aafd4e8a6c8605bc0200d35679a41c
Sha256 a70a66a4530d9913f65f5d40945e03a2441ac077c62edc1b4e3f4343555c6943
Sha384 af854ef39c4bf707321272e9da8168a924a35d0e4245bee60b433290dca2104985bfe4b8a0ae672b1fddc4350531f3c4
Sha512 2b6d0e6d0218036f7b6c9269d342d9b9167c796848d41344325732871b6b9e3bf539d24298f1741ec9f45a0774ace68b4441031afb20c719847b65e5c02cffa2
SSDeep 24576:nz7eGUgn/BFIqVHEvmOg+b3JNNAsjbjoEat5Oz4ZOotKTTnmyxdx1JsnjS/rlD:z1kljCqbMpT4OmUnjS/rl
TLSH E585AD017E44CE11F0195333C2EF458897B0A9517AA6E72B7DBA37AE64123A37C0D9DB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
Dd0Sx2UxBstr7kwoKd.T7IFRFJpiIo0lggtEr
ShU4gR4Ao2tNE0t34I.BJT90do3q7yJOobyOg
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Gn1Upe
Full Name
Gn1Upe
EntryPoint
System.Void LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::zkKptOGQAA()
Scope Name
Gn1Upe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EYMjfYldPW6LpLm9fgIw
Assembly Version
1.1.4.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::zkKptOGQAA()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void qnjO2UWj5y1NXlqeys2.c5MPojWwm2D81m8nZWq::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::MIUpURTtIb
callvirt System.Void TW8sJJdwXMqxSb2050y.oJaaJMd7F48nAkv6THk::oUA2eNUfZU()
nop <null>
ret <null>
Module Name
Gn1Upe
Full Name
Gn1Upe
EntryPoint
System.Void LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::zkKptOGQAA()
Scope Name
Gn1Upe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
EYMjfYldPW6LpLm9fgIw
Assembly Version
1.1.4.8
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::zkKptOGQAA()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void qnjO2UWj5y1NXlqeys2.c5MPojWwm2D81m8nZWq::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object LDGqsadJEn8nRCMDsDp.wCQM3Md3IrYU1wNYoBZ::MIUpURTtIb
callvirt System.Void TW8sJJdwXMqxSb2050y.oJaaJMd7F48nAkv6THk::oUA2eNUfZU()
nop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙