Malicious
Malicious

93d766dd78be7c3f2a54af0605c89014

PE Executable
MD5: 93d766dd78be7c3f2a54af0605c89014
Size: 1.39 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 93d766dd78be7c3f2a54af0605c89014
Sha1 45fe16ae9f2d825714581ecc691741bd06ef2cfb
Sha256 90cd82d7296ca7b11480d47e6e7d94bd69d586a942d39ae8c899bf5df083c46a
Sha384 d7c4fc700b3443bcf7e9d9ca26df8d882101f76f5cde9c8ac119ba597ec6b1ded1e0507882ca693cefefe90c1179a3e5
Sha512 024c14bd7c4c9b833156cb85e96d3243a0f62d5a456c516b0bb35f510b4e173fa27fb5bc9e9cda0d1f58dfb382b80abc415aef16b26feff1de64ae463c2d6713
SSDeep 24576:I0mcZSTTfBg1p3AT0/jYg7B07HcYeeMuy2fCTFfar4K9pCRmLBBElijf0rtVy:ic8TTfBMwT0bYgi7HcjeXygCFE9p4mLJ
TLSH 3F552358222BC827D462ABB35AC2D07003708D59F413D257AFDA3DDF7625B9A4EE0793
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
fO.cm.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SaltPan.Properties.Resources.resources
IMG
[NBF]root.Data
ULfx
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
xLrm.exe
Full Name
xLrm.exe
EntryPoint
System.Void gDU.CDD::gDg()
Scope Name
xLrm.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xLrm
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
262
Main Method
System.Void gDU.CDD::gDg()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0023: call System.Void qDA.bDG::DXy()
nop <null>
newobj System.Void fO.cm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0005: nop
call System.Void qDA.bDG::DXy()
br IL_0013: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0007: nop
Module Name
xLrm.exe
Full Name
xLrm.exe
EntryPoint
System.Void gDU.CDD::gDg()
Scope Name
xLrm.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xLrm
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
262
Main Method
System.Void gDU.CDD::gDg()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0023: call System.Void qDA.bDG::DXy()
nop <null>
newobj System.Void fO.cm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0005: nop
call System.Void qDA.bDG::DXy()
br IL_0013: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0007: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
fO.cm.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SaltPan.Properties.Resources.resources
IMG
[NBF]root.Data
ULfx
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙