Malicious
Malicious

ad6a7fe9c9d21c0f6d68b3d44f966150

PE Executable
MD5: ad6a7fe9c9d21c0f6d68b3d44f966150
Size: 885.76 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 ad6a7fe9c9d21c0f6d68b3d44f966150
Sha1 572b625b6f48b64ec15e038500c1d196f387e808
Sha256 10333cfe3b8de037f163d4e80af8e1f18cd5ca7af555dbc9c1da5409925a079d
Sha384 6cd3f152699ebab4a22e6b5a2ec86a92feac894b81dfe0e97e4eac518e233dd03c86e08c3ff5bd8cbd2d6c96f9df4d0a
Sha512 7d8e6a074e6be9374343bc29816980a5f4537a17b272a46adc12b6563670a70daa721549f080753f6d6eb00a22cf131976c0447ed734d963872655e2557ecb7a
SSDeep 12288:9Aoa3fikONrtry2VNX/tK4hSq8/W1fz795m8yDllVqlbc7n4P0:6HvifFy2Vp84GW1vS/VqJK
TLSH BE158B04215BCA23C25526B0C9B2D2F90374DE54D932C36B5AEA7DBB7F35FF1A5402A2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Hq.MC.resources
$this.Icon
[NBF]root.IconData
gxSG.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
FlaxRetting.Properties.Resources.resources
icons8_graph_report_50
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_purchase_order_50
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_customer_26
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_package_64
[NBF]root.Data
[NBF]root.Data-preview.png
BwuT
[NBF]root.Data
[NBF]root.Data-preview.png
Btlj
[NBF]root.Data
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Module Name
gxSG.exe
Full Name
gxSG.exe
EntryPoint
System.Void Ml.Ki::yb()
Scope Name
gxSG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gxSG
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Info
PE Detect: PeReader OK (file layout)
Total Strings
257
Main Method
System.Void Ml.Ki::yb()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
call System.Void uGj.kGf::Ps9()
br IL_001B: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void uGj.kGf::Ps9()
nop <null>
newobj System.Void n6.HB::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002B: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_000F: nop
Module Name
gxSG.exe
Full Name
gxSG.exe
EntryPoint
System.Void Ml.Ki::yb()
Scope Name
gxSG.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
gxSG
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
257
Main Method
System.Void Ml.Ki::yb()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
call System.Void uGj.kGf::Ps9()
br IL_001B: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void uGj.kGf::Ps9()
nop <null>
newobj System.Void n6.HB::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002B: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_000F: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Hq.MC.resources
$this.Icon
[NBF]root.IconData
gxSG.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
FlaxRetting.Properties.Resources.resources
icons8_graph_report_50
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_purchase_order_50
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_customer_26
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_package_64
[NBF]root.Data
[NBF]root.Data-preview.png
BwuT
[NBF]root.Data
[NBF]root.Data-preview.png
Btlj
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙