Malicious
Malicious

83b5deccf643e9ee89bbedebad07a727

PE Executable
MD5: 83b5deccf643e9ee89bbedebad07a727
Size: 1.23 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 83b5deccf643e9ee89bbedebad07a727
Sha1 96862fd5f2765d53c5eef4b030aed2f3013b06f1
Sha256 9fd56099a09d95c176edc8ef6486393f79db311c6243453c697358c411d6378d
Sha384 9e7a13da0340d014af8ccca23fcbaef367429816c757e47ec8d570e913c7a410e0eb0ef074f6300e4274f385d1f50720
Sha512 ff3774aeb5717c6410854c93b2a9f325134526733992a865373983317956b1f8e46a76d09d6dc197e69f9775aba3bbca339cbdc751762777db641cb90d29322e
SSDeep 24576:ysAqj0qdPtD+t6gLvYIPpGizWUlR8fxPcpsKAPw3XAKOcYhGHY:rXIQIPDzWYR8fupsKLXYU
TLSH B14512246326E412C62497354AE2E1B407B84ED9F412E317AFE87FDB772AF160E44787
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
cV.AY.resources
$this.Icon
[NBF]root.IconData
emz.Vmx.resources
NJ
[NBF]root.Data
DyI.wyV.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
QQC.Properties.Resources.resources
h17 (5)
[NBF]root.Data
[NBF]root.Data-preview.png
h17 (4)
[NBF]root.Data
[NBF]root.Data-preview.png
a4
[NBF]root.Data
[NBF]root.Data-preview.png
h21
[NBF]root.Data
[NBF]root.Data-preview.png
a9 (7)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
a9 (2)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
xCie
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path pe:exe>img>img
Shape pe:exe>img>img
malicious 3 nodes
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
mUaD.exe
Full Name
mUaD.exe
EntryPoint
System.Void Ns2.As3::OsA()
Scope Name
mUaD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mUaD
Assembly Version
5.3.7.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
434
Info
PDB Path: mUaD.pdb
Main Method
System.Void Ns2.As3::OsA()
Main IL Instruction Count
12
Main IL
br IL_000F: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
call System.Void KKw.eKM::EOk()
br IL_0019: newobj System.Void emz.Vmx::.ctor()
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0029: ldc.i4.0
newobj System.Void emz.Vmx::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0028: ret
ret <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void KKw.eKM::EOk()
Module Name
mUaD.exe
Full Name
mUaD.exe
EntryPoint
System.Void Ns2.As3::OsA()
Scope Name
mUaD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mUaD
Assembly Version
5.3.7.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
434
Main Method
System.Void Ns2.As3::OsA()
Main IL Instruction Count
12
Main IL
br IL_000F: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
call System.Void KKw.eKM::EOk()
br IL_0019: newobj System.Void emz.Vmx::.ctor()
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0029: ldc.i4.0
newobj System.Void emz.Vmx::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0028: ret
ret <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void KKw.eKM::EOk()
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
cV.AY.resources
$this.Icon
[NBF]root.IconData
emz.Vmx.resources
NJ
[NBF]root.Data
DyI.wyV.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
QQC.Properties.Resources.resources
h17 (5)
[NBF]root.Data
[NBF]root.Data-preview.png
h17 (4)
[NBF]root.Data
[NBF]root.Data-preview.png
a4
[NBF]root.Data
[NBF]root.Data-preview.png
h21
[NBF]root.Data
[NBF]root.Data-preview.png
a9 (7)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
a9 (2)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
xCie
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙