Malicious
Malicious

a7ae6bfb61ecc81b5425c311f050a518

PE Executable
MD5: a7ae6bfb61ecc81b5425c311f050a518
Size: 1.24 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 a7ae6bfb61ecc81b5425c311f050a518
Sha1 3872008acee3624bf9a290fe384e399958973acd
Sha256 7250576a3cb7164bf383d89683267604dd1a5d36e1a35f22b5bef2d9f29402e5
Sha384 1cb0576b64dd2c2a8bef3d1c98ecc8043f5830254017a5193759717200b6301b2dedb21a6f4f6ab92c2d2f4a9ea676c8
Sha512 731f4b4c171b9b619be1d1ed057bbae18c3755d83b5ce363f3683edbbae9041437efba7ec5a928558ef7ab418580538956194847db4e83af0b28671e4803c54b
SSDeep 24576:cWViPkKzZl+cccZK8pn/TboYll5tFhh3pQ4+6oOF6uraCDB:ckisKzZlfccZxpLboYZtFb3aZMDB
TLSH DD4502186A5BEC03C8B503358AE2F6B043F56E4DE522D25B8FEA2CDB3921BD519D4353
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0UPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
zaXu.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SemaphoreLine.Properties.Resources.resources
GUI
[NBF]root.Data
qhxP
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
zaXu.exe
Full Name
zaXu.exe
EntryPoint
System.Void UJ.Jo::F3()
Scope Name
zaXu.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
zaXu
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
417
Main Method
System.Void UJ.Jo::F3()
Main IL Instruction Count
16
Main IL
br IL_001B: nop
call System.Void kwU.wwL::xdG()
br IL_0028: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void kwU.wwL::xdG()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_000F: nop
nop <null>
ret <null>
nop <null>
newobj System.Void Bxi.Wxy::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0026: nop
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
zaXu.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SemaphoreLine.Properties.Resources.resources
GUI
[NBF]root.Data
qhxP
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙