Suspicious
Suspect

b71801cb375be6f6d78fa688c81664d5

Share on LinkedIn
Print
PE Executable
MD5: b71801cb375be6f6d78fa688c81664d5
Size: 1.12 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 b71801cb375be6f6d78fa688c81664d5
Sha1 15e4b9679d5252925da739565c9053fadc011b15
Sha256 fa42af75b40265c9bc250ca078e9195ed3531fd96ffd14ece5d9fc9677a1dafa
Sha384 3ca64fe8cf416a4e76b81dac297109e03bc74908fbf6a7c5f37dd43609e400e5ff7fd729f628981717b41d3a09277b65
Sha512 7d4c3e3429d116cef77ecb93705c190b6395c8fdcd8f6c6e37ed15d4e1662a1540789e643bf80e80f01b920e97c913b1013a5297b70098095f171bf3376b894b
SSDeep 24576:iXMSvbSx4nWiPzAPzTE0OfR80XybH350qRno0G1:3kbSSWyAPzY0Si0K5lj
TLSH 083501365E836B14C67D0E7CC067589C23F4CA17A226E76B3FEC11E48B66FD49A23056
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Gertali.huta.asp
Mzm5bH4nX3.Resources.resources
5c25b9e03e5fd6.Resources.resources
615ed6b60
[NBF]root.Data
615ed6b61
[NBF]root.Data
615ed6b610
[NBF]root.Data
615ed6b611
[NBF]root.Data
615ed6b612
[NBF]root.Data
615ed6b613
[NBF]root.Data
615ed6b614
[NBF]root.Data
615ed6b615
[NBF]root.Data
615ed6b616
[NBF]root.Data
615ed6b617
[NBF]root.Data
615ed6b618
[NBF]root.Data
615ed6b619
[NBF]root.Data
615ed6b62
[NBF]root.Data
615ed6b620
[NBF]root.Data
615ed6b621
[NBF]root.Data
615ed6b622
[NBF]root.Data
615ed6b63
[NBF]root.Data
615ed6b64
[NBF]root.Data
615ed6b65
[NBF]root.Data
615ed6b66
[NBF]root.Data
615ed6b67
[NBF]root.Data
615ed6b68
[NBF]root.Data
615ed6b69
[NBF]root.Data
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Mzm5bH4nX3
Full Name
Mzm5bH4nX3
EntryPoint
System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
Scope Name
Mzm5bH4nX3
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Mzm5bH4nX3
Assembly Version
23.6.5.146
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void cc2Q7Nkayb3.4esWYx3::.ctor()
stloc.0 <null>
ret <null>
ldtoken System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
pop <null>
ret <null>
Module Name
Mzm5bH4nX3
Full Name
Mzm5bH4nX3
EntryPoint
System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
Scope Name
Mzm5bH4nX3
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Mzm5bH4nX3
Assembly Version
23.6.5.146
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void cc2Q7Nkayb3.4esWYx3::.ctor()
stloc.0 <null>
ret <null>
ldtoken System.Void cc2Q7Nkayb3.4esWYx3/1tzLt3PeCbd9s.Xj6_4qrGw5Dai::Xr5t2Wiqa()
pop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙