Malicious
Malicious

83b5deccf643e9ee89bbedebad07a727

Share on LinkedIn
Print
PE Executable
MD5: 83b5deccf643e9ee89bbedebad07a727
Size: 1.23 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 83b5deccf643e9ee89bbedebad07a727
Sha1 96862fd5f2765d53c5eef4b030aed2f3013b06f1
Sha256 9fd56099a09d95c176edc8ef6486393f79db311c6243453c697358c411d6378d
Sha384 9e7a13da0340d014af8ccca23fcbaef367429816c757e47ec8d570e913c7a410e0eb0ef074f6300e4274f385d1f50720
Sha512 ff3774aeb5717c6410854c93b2a9f325134526733992a865373983317956b1f8e46a76d09d6dc197e69f9775aba3bbca339cbdc751762777db641cb90d29322e
SSDeep 24576:ysAqj0qdPtD+t6gLvYIPpGizWUlR8fxPcpsKAPw3XAKOcYhGHY:rXIQIPDzWYR8fupsKLXYU
TLSH B14512246326E412C62497354AE2E1B407B84ED9F412E317AFE87FDB772AF160E44787
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
cV.AY.resources
$this.Icon
[NBF]root.IconData
emz.Vmx.resources
NJ
[NBF]root.Data
DyI.wyV.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
QQC.Properties.Resources.resources
h17 (5)
[NBF]root.Data
[NBF]root.Data-preview.png
h17 (4)
[NBF]root.Data
[NBF]root.Data-preview.png
a4
[NBF]root.Data
[NBF]root.Data-preview.png
h21
[NBF]root.Data
[NBF]root.Data-preview.png
a9 (7)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
a9 (2)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
xCie
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path pe:exe>img>img
Shape pe:exe>img>img
malicious 3 nodes
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
mUaD.exe
Full Name
mUaD.exe
EntryPoint
System.Void Ns2.As3::OsA()
Scope Name
mUaD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mUaD
Assembly Version
5.3.7.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
434
Info
PDB Path: mUaD.pdb
Main Method
System.Void Ns2.As3::OsA()
Main IL Instruction Count
12
Main IL
br IL_000F: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
call System.Void KKw.eKM::EOk()
br IL_0019: newobj System.Void emz.Vmx::.ctor()
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0029: ldc.i4.0
newobj System.Void emz.Vmx::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0028: ret
ret <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void KKw.eKM::EOk()
Module Name
mUaD.exe
Full Name
mUaD.exe
EntryPoint
System.Void Ns2.As3::OsA()
Scope Name
mUaD.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mUaD
Assembly Version
5.3.7.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
434
Main Method
System.Void Ns2.As3::OsA()
Main IL Instruction Count
12
Main IL
br IL_000F: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
call System.Void KKw.eKM::EOk()
br IL_0019: newobj System.Void emz.Vmx::.ctor()
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0029: ldc.i4.0
newobj System.Void emz.Vmx::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0028: ret
ret <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void KKw.eKM::EOk()
An error has occurred. This application may no longer respond until reloaded. Reload 🗙