Suspicious
Suspect

7588f296973b9d2c0f21e93e85766c62

PE Executable
MD5: 7588f296973b9d2c0f21e93e85766c62
Size: 1.08 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 7588f296973b9d2c0f21e93e85766c62
Sha1 33baedf689f584c2cdb2b63a5b9885dffbd34549
Sha256 70c0ccac3248ade2286752d2ca5e709bf14df458ce37171dea4392e5fc6c0535
Sha384 8647aa6ba513a4324e792104278b6041d64958f7862b16c358ae96a8b2de132ca36c4afec8bfbb796b59f648bdc15741
Sha512 64dfb237348912727b1be4540564b92562b5e0c42565f0387ea7ffa2a911bcaf3c0753b507a9a850c1ea27c308b03fd5f13ba12b5433930b16ff14235f691d6e
SSDeep 24576:+x9fez3N2UVgc1bdKwW/ew3T9HpJ9+gKsRLeiK1zyss0:ue88dRGF39+gpeLl
TLSH F835F1264E472B55CA3D8BB8C166089863F0C65B8312E76F3FFC01F49FA27855B63546
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Ⴄ.fZb92ebRxmP.resources
5Morfp7Ps0.g.resources
7db7576650e0d5.Resources.resources
b7f210780
[NBF]root.Data
b7f210781
[NBF]root.Data
b7f2107810
[NBF]root.Data
b7f2107811
[NBF]root.Data
b7f2107812
[NBF]root.Data
b7f2107813
[NBF]root.Data
b7f2107814
[NBF]root.Data
b7f2107815
[NBF]root.Data
b7f2107816
[NBF]root.Data
b7f2107817
[NBF]root.Data
b7f2107818
[NBF]root.Data
b7f2107819
[NBF]root.Data
b7f210782
[NBF]root.Data
b7f2107820
[NBF]root.Data
b7f2107821
[NBF]root.Data
b7f2107822
[NBF]root.Data
b7f210783
[NBF]root.Data
b7f210784
[NBF]root.Data
b7f210785
[NBF]root.Data
b7f210786
[NBF]root.Data
b7f210787
[NBF]root.Data
b7f210788
[NBF]root.Data
b7f210789
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Module Name
5Morfp7Ps0
Full Name
5Morfp7Ps0
EntryPoint
System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
Scope Name
5Morfp7Ps0
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
5Morfp7Ps0
Assembly Version
20.3.49.115
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Info
PE Detect: PeReader OK (file layout)
Total Strings
0
Main Method
System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
Main IL Instruction Count
9
Main IL
nop <null>
newobj System.Void System.Windows.Forms.Form::.ctor()
stloc.1 <null>
newobj System.Void 0Qyoa6rK3aAwkG.Bjx9n1yR6Xipw::.ctor()
stloc.2 <null>
ret <null>
ldtoken System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
pop <null>
ret <null>
Module Name
5Morfp7Ps0
Full Name
5Morfp7Ps0
EntryPoint
System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
Scope Name
5Morfp7Ps0
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
5Morfp7Ps0
Assembly Version
20.3.49.115
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
Main IL Instruction Count
9
Main IL
nop <null>
newobj System.Void System.Windows.Forms.Form::.ctor()
stloc.1 <null>
newobj System.Void 0Qyoa6rK3aAwkG.Bjx9n1yR6Xipw::.ctor()
stloc.2 <null>
ret <null>
ldtoken System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
pop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Ⴄ.fZb92ebRxmP.resources
5Morfp7Ps0.g.resources
7db7576650e0d5.Resources.resources
b7f210780
[NBF]root.Data
b7f210781
[NBF]root.Data
b7f2107810
[NBF]root.Data
b7f2107811
[NBF]root.Data
b7f2107812
[NBF]root.Data
b7f2107813
[NBF]root.Data
b7f2107814
[NBF]root.Data
b7f2107815
[NBF]root.Data
b7f2107816
[NBF]root.Data
b7f2107817
[NBF]root.Data
b7f2107818
[NBF]root.Data
b7f2107819
[NBF]root.Data
b7f210782
[NBF]root.Data
b7f2107820
[NBF]root.Data
b7f2107821
[NBF]root.Data
b7f2107822
[NBF]root.Data
b7f210783
[NBF]root.Data
b7f210784
[NBF]root.Data
b7f210785
[NBF]root.Data
b7f210786
[NBF]root.Data
b7f210787
[NBF]root.Data
b7f210788
[NBF]root.Data
b7f210789
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙