Suspicious
Suspect

b71801cb375be6f6d78fa688c81664d5

PE Executable
MD5: b71801cb375be6f6d78fa688c81664d5
Size: 1.12 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 b71801cb375be6f6d78fa688c81664d5
Sha1 15e4b9679d5252925da739565c9053fadc011b15
Sha256 fa42af75b40265c9bc250ca078e9195ed3531fd96ffd14ece5d9fc9677a1dafa
Sha384 3ca64fe8cf416a4e76b81dac297109e03bc74908fbf6a7c5f37dd43609e400e5ff7fd729f628981717b41d3a09277b65
Sha512 7d4c3e3429d116cef77ecb93705c190b6395c8fdcd8f6c6e37ed15d4e1662a1540789e643bf80e80f01b920e97c913b1013a5297b70098095f171bf3376b894b
SSDeep 24576:iXMSvbSx4nWiPzAPzTE0OfR80XybH350qRno0G1:3kbSSWyAPzY0Si0K5lj
TLSH 083501365E836B14C67D0E7CC067589C23F4CA17A226E76B3FEC11E48B66FD49A23056
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Gertali.huta.asp
Mzm5bH4nX3.Resources.resources
5c25b9e03e5fd6.Resources.resources
615ed6b60
[NBF]root.Data
615ed6b61
[NBF]root.Data
615ed6b610
[NBF]root.Data
615ed6b611
[NBF]root.Data
615ed6b612
[NBF]root.Data
615ed6b613
[NBF]root.Data
615ed6b614
[NBF]root.Data
615ed6b615
[NBF]root.Data
615ed6b616
[NBF]root.Data
615ed6b617
[NBF]root.Data
615ed6b618
[NBF]root.Data
615ed6b619
[NBF]root.Data
615ed6b62
[NBF]root.Data
615ed6b620
[NBF]root.Data
615ed6b621
[NBF]root.Data
615ed6b622
[NBF]root.Data
615ed6b63
[NBF]root.Data
615ed6b64
[NBF]root.Data
615ed6b65
[NBF]root.Data
615ed6b66
[NBF]root.Data
615ed6b67
[NBF]root.Data
615ed6b68
[NBF]root.Data
615ed6b69
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Mzm5bH4nX3
Full Name
Mzm5bH4nX3
EntryPoint
System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
Scope Name
Mzm5bH4nX3
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Mzm5bH4nX3
Assembly Version
23.6.5.146
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void cc2Q7Nkayb3.4esWYx3::.ctor()
stloc.0 <null>
ret <null>
ldtoken System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
pop <null>
ret <null>
Module Name
Mzm5bH4nX3
Full Name
Mzm5bH4nX3
EntryPoint
System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
Scope Name
Mzm5bH4nX3
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Mzm5bH4nX3
Assembly Version
23.6.5.146
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void cc2Q7Nkayb3.4esWYx3::.ctor()
stloc.0 <null>
ret <null>
ldtoken System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
pop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Gertali.huta.asp
Mzm5bH4nX3.Resources.resources
5c25b9e03e5fd6.Resources.resources
615ed6b60
[NBF]root.Data
615ed6b61
[NBF]root.Data
615ed6b610
[NBF]root.Data
615ed6b611
[NBF]root.Data
615ed6b612
[NBF]root.Data
615ed6b613
[NBF]root.Data
615ed6b614
[NBF]root.Data
615ed6b615
[NBF]root.Data
615ed6b616
[NBF]root.Data
615ed6b617
[NBF]root.Data
615ed6b618
[NBF]root.Data
615ed6b619
[NBF]root.Data
615ed6b62
[NBF]root.Data
615ed6b620
[NBF]root.Data
615ed6b621
[NBF]root.Data
615ed6b622
[NBF]root.Data
615ed6b63
[NBF]root.Data
615ed6b64
[NBF]root.Data
615ed6b65
[NBF]root.Data
615ed6b66
[NBF]root.Data
615ed6b67
[NBF]root.Data
615ed6b68
[NBF]root.Data
615ed6b69
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙