Malicious
9a3d0e61430550fc5f788c7cef6c1644
PE Executable
MD5: 9a3d0e61430550fc5f788c7cef6c1644
Size: 245.25 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 9a3d0e61430550fc5f788c7cef6c1644 |
| Sha1 | c5dfb45b76144ce20870bbdd5defb0a51989e0bb |
| Sha256 | 89c1a2c27470e898513e95d6175c382cd5a33fd6a509cde700b213214ecf0b80 |
| Sha384 | 27006f95318622075f809719b6de91d86229b7fe1b237fb222a6e7e9f1f0e9055735b53163e61fa3e560391b27215726 |
| Sha512 | 82205766ca692128d8cae2624d46b61882efa3035c8152b22997e4600da616dd7b3633a86550bd8608b16813195f86d328fda8c77711e4acc97fd0cff58a7a61 |
| SSDeep | 3072:E4liq6CyZVc/2MKc2BLIg0THo9rG8KaG5jnThCqYufzz:niq6CyDY2Mk+sq8KaWTk |
| TLSH | D3340F027F88E715E1A93E3782EF6C2453B2B4C71633C60BAF49AB5524516826C7E72D |
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | 8N57q4CivJ |
| Full Name | 8N57q4CivJ |
| EntryPoint | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Scope Name | 8N57q4CivJ |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | f45b853c-c9d3-495e-9acb-d41a4a90029f |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 1093 |
| Main Method | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Main IL Instruction Count | 62 |
| Main IL | |
| Module Name | 8N57q4CivJ |
| Full Name | 8N57q4CivJ |
| EntryPoint | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Scope Name | 8N57q4CivJ |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | f45b853c-c9d3-495e-9acb-d41a4a90029f |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 1093 |
| Main Method | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Main IL Instruction Count | 62 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.