Malicious
Malicious

90606f943f0360cda289735b31ef836f

PE Executable
MD5: 90606f943f0360cda289735b31ef836f
Size: 1.74 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 90606f943f0360cda289735b31ef836f
Sha1 f03f8bf1cab0a3772864c37678ec54d411fa1ff3
Sha256 f0ac5a212ee1e3acb68b27dfdd8e3b9f46be4d6d49ec0e843b2c0cb832145873
Sha384 91f8f5761fd6c2ecc3ec3913ad9f851a59b1d319a18afc2235106b659663b54e47be3b3dd0e4dff998c64de2074a6b8d
Sha512 3bfc1cc2114ea381afa917a53d5d2cb38a344c710dde5ce7b18ae1270a99216f8be7261a4a25832ad23c228cbef3c6c5f961f10e7c5ffe0bd317d18b5fbef5fc
SSDeep 49152:Q5kwtBYYCP6ueB/If+t/Hjn4/5FuKmLusR5r7U:Q5kwtBTBx9DwfLmCu7
TLSH 418512986647E903E66297751DF1E1B517790FDAE912E20B1FE87DEB7A22F440C80383
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
YQgh.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
HospitalWard.Properties.Resources.resources
NJ
[NBF]root.Data
h21
[NBF]root.Data
[NBF]root.Data-preview.png
lJTG
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Module Name
YQgh.exe
Full Name
YQgh.exe
EntryPoint
System.Void jTQ.XT8::JTi()
Scope Name
YQgh.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YQgh
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Info
PE Detect: PeReader OK (file layout)
Total Strings
316
Main Method
System.Void jTQ.XT8::JTi()
Main IL Instruction Count
16
Main IL
br IL_0007: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0012: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_001E: call System.Void Arm.vrB::AoN()
call System.Void Arm.vrB::AoN()
br IL_0028: nop
nop <null>
newobj System.Void Ia.Ys::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0005: nop
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
YQgh.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
HospitalWard.Properties.Resources.resources
NJ
[NBF]root.Data
h21
[NBF]root.Data
[NBF]root.Data-preview.png
lJTG
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙