Malicious
Malicious

986f49b76d3d7dfcaa44ccefa6bc3ae0

PE Executable
MD5: 986f49b76d3d7dfcaa44ccefa6bc3ae0
Size: 846.85 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 986f49b76d3d7dfcaa44ccefa6bc3ae0
Sha1 b005bbb4ac1b175ee12d5e1a76ea48f81b266858
Sha256 3bb89c9e7eff35cd476e57b77412497cacd3833cf8d7f7139f6671a1284ac16c
Sha384 6562ecbe51645367a20f638b6e98f114f2c66cadcc88c8c7def55a3473b013b655e497e8af3375a69f813fbf0cfac2ba
Sha512 9accebaf1fd690a25df99cd171057b3d8779e177b5e9836e38f8c2fabb1209b7979aa95d5f932c2e172c918ab164721480df77344d84826d6c2e270c62745cce
SSDeep 12288:7btgaTd9X5xkUhCtQpF3ZWR5Lv7kPGztku1Y3EquzkPMczoEyG7J/ZiUJy:RpFYR5LvoPIku2pscEEyINJ
TLSH 8305F114AAABDC13C5B2073589E0E27103F19D4AF921D35B4FFA6DD73A12BC658C8693
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
wARB.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SemaphoreLine.Properties.Resources.resources
GUI
[NBF]root.Data
rEzl
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Module Name
wARB.exe
Full Name
wARB.exe
EntryPoint
System.Void sG.CP::UU()
Scope Name
wARB.exe
Info
PE Detect: PeReader OK (file layout)
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wARB
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
417
Main Method
System.Void sG.CP::UU()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0023: call System.Void kdt.jdQ::QOb()
nop <null>
newobj System.Void ghe.ThF::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0021: nop
nop <null>
ret <null>
call System.Void kdt.jdQ::QOb()
br IL_0011: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: nop
Module Name
wARB.exe
Full Name
wARB.exe
EntryPoint
System.Void sG.CP::UU()
Scope Name
wARB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
wARB
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
417
Main Method
System.Void sG.CP::UU()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0023: call System.Void kdt.jdQ::QOb()
nop <null>
newobj System.Void ghe.ThF::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0021: nop
nop <null>
ret <null>
call System.Void kdt.jdQ::QOb()
br IL_0011: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
wARB.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SemaphoreLine.Properties.Resources.resources
GUI
[NBF]root.Data
rEzl
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙