Suspicious
Suspect

7588f296973b9d2c0f21e93e85766c62

Share on LinkedIn
Print
PE Executable
MD5: 7588f296973b9d2c0f21e93e85766c62
Size: 1.08 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 7588f296973b9d2c0f21e93e85766c62
Sha1 33baedf689f584c2cdb2b63a5b9885dffbd34549
Sha256 70c0ccac3248ade2286752d2ca5e709bf14df458ce37171dea4392e5fc6c0535
Sha384 8647aa6ba513a4324e792104278b6041d64958f7862b16c358ae96a8b2de132ca36c4afec8bfbb796b59f648bdc15741
Sha512 64dfb237348912727b1be4540564b92562b5e0c42565f0387ea7ffa2a911bcaf3c0753b507a9a850c1ea27c308b03fd5f13ba12b5433930b16ff14235f691d6e
SSDeep 24576:+x9fez3N2UVgc1bdKwW/ew3T9HpJ9+gKsRLeiK1zyss0:ue88dRGF39+gpeLl
TLSH F835F1264E472B55CA3D8BB8C166089863F0C65B8312E76F3FFC01F49FA27855B63546
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Ⴄ.fZb92ebRxmP.resources
5Morfp7Ps0.g.resources
7db7576650e0d5.Resources.resources
b7f210780
[NBF]root.Data
b7f210781
[NBF]root.Data
b7f2107810
[NBF]root.Data
b7f2107811
[NBF]root.Data
b7f2107812
[NBF]root.Data
b7f2107813
[NBF]root.Data
b7f2107814
[NBF]root.Data
b7f2107815
[NBF]root.Data
b7f2107816
[NBF]root.Data
b7f2107817
[NBF]root.Data
b7f2107818
[NBF]root.Data
b7f2107819
[NBF]root.Data
b7f210782
[NBF]root.Data
b7f2107820
[NBF]root.Data
b7f2107821
[NBF]root.Data
b7f2107822
[NBF]root.Data
b7f210783
[NBF]root.Data
b7f210784
[NBF]root.Data
b7f210785
[NBF]root.Data
b7f210786
[NBF]root.Data
b7f210787
[NBF]root.Data
b7f210788
[NBF]root.Data
b7f210789
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Module Name
5Morfp7Ps0
Full Name
5Morfp7Ps0
EntryPoint
System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
Scope Name
5Morfp7Ps0
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
5Morfp7Ps0
Assembly Version
20.3.49.115
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Info
PE Detect: PeReader OK (file layout)
Total Strings
0
Main Method
System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
Main IL Instruction Count
9
Main IL
nop <null>
newobj System.Void System.Windows.Forms.Form::.ctor()
stloc.1 <null>
newobj System.Void 0Qyoa6rK3aAwkG.Bjx9n1yR6Xipw::.ctor()
stloc.2 <null>
ret <null>
ldtoken System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
pop <null>
ret <null>
Module Name
5Morfp7Ps0
Full Name
5Morfp7Ps0
EntryPoint
System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
Scope Name
5Morfp7Ps0
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
5Morfp7Ps0
Assembly Version
20.3.49.115
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
Main IL Instruction Count
9
Main IL
nop <null>
newobj System.Void System.Windows.Forms.Form::.ctor()
stloc.1 <null>
newobj System.Void 0Qyoa6rK3aAwkG.Bjx9n1yR6Xipw::.ctor()
stloc.2 <null>
ret <null>
ldtoken System.Void kn7Za5.pYd0as5D3/4orT_Xd8Q9d.Txd7i1dL6NfcCz::2ajYK7mr5eJf()
pop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙