Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 ba392b9ef395210c60902a8d64efe4dc
Sha1 f3314c5f820237b7471f3fdec64e47fb8a7f33fb
Sha256 08edc0df73427e600402e4f2529d5284b17ccb16f4c24594869ca7e6ddc33936
Sha384 3cf3cc54868b02a3d733ed37dcb11caf2d6b7d826f6a196736de0827f8065b83ce415b45e384bbcc55d15acd28bb13d2
Sha512 c82bd6dbd1992d4b8ea030580f9b4d77c11cead13f076a0490d5b7326fb3c5266b9c82fc7eb120db8e518073a634c224af2c58e528685c735c23b517ec4021ab
SSDeep 12288:5AGpI63dMfYBbkILPPCTABbBlfWC8UH6pcJaTLWdDBGu7q/PD0vlVEDcBy+32:zn3lkwPEABjWC9H6aJNdtgzKEk93
TLSH C135F11B23EC0B25F1BF1F78DA7811054BF1B917C522E36E2E9541E99D22B849E92373
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Reflective Loader
Malicious
Overlay_fef55cbd.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
AttachedParser.TokenParser
OperationalParser.HiddenParser
DetachedParser.ParserFactory
ParserEditor.ParserElement
.Net Resources
Maselatki.562567.tsx
oMj24mm.Resources.resources
ab1a64766075e4.Resources.resources
b92bf1a60
[NBF]root.Data
b92bf1a61
[NBF]root.Data
b92bf1a610
[NBF]root.Data
b92bf1a611
[NBF]root.Data
b92bf1a612
[NBF]root.Data
b92bf1a613
[NBF]root.Data
b92bf1a614
[NBF]root.Data
b92bf1a615
[NBF]root.Data
b92bf1a616
[NBF]root.Data
b92bf1a617
[NBF]root.Data
b92bf1a618
[NBF]root.Data
b92bf1a619
[NBF]root.Data
b92bf1a62
[NBF]root.Data
b92bf1a620
[NBF]root.Data
b92bf1a621
[NBF]root.Data
b92bf1a622
[NBF]root.Data
b92bf1a623
[NBF]root.Data
b92bf1a624
[NBF]root.Data
b92bf1a63
[NBF]root.Data
b92bf1a64
[NBF]root.Data
b92bf1a65
[NBF]root.Data
b92bf1a66
[NBF]root.Data
b92bf1a67
[NBF]root.Data
b92bf1a68
[NBF]root.Data
b92bf1a69
[NBF]root.Data
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path pe:exe>pe:dll~T1059.007>pe:rsrc>bin
Shape pe:exe>pe:dll>pe:rsrc>bin
malicious 4 nodes
Path pe:exe>pe:dll~T1059.007>bin
Shape pe:exe>pe:dll>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
oMj24mm
Full Name
oMj24mm
EntryPoint
System.Void oMj24mm.Zbw2f7Gqx::Xsx27Eqnz()
Scope Name
oMj24mm
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oMj24mm
Assembly Version
4.1.21.99
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1083
Main Method
System.Void oMj24mm.Zbw2f7Gqx::Xsx27Eqnz()
Main IL Instruction Count
51
Main IL
nop <null>
nop <null>
ldc.i4.s 25
stloc.2 <null>
ldloc.2 <null>
ldc.i4.1 <null>
sub.ovf <null>
ldc.i4.1 <null>
add.ovf <null>
newarr System.Object
stloc.3 <null>
ldloc.3 <null>
ldc.i4.0 <null>
ldstr 562567.tsx
stelem.ref <null>
ldloc.3 <null>
ldc.i4.1 <null>
ldc.i4 8848948
stloc.s V_4
ldloca.s V_4
call System.String System.Int32::ToString()
stelem.ref <null>
ldloc.3 <null>
ldc.i4.2 <null>
ldloc.3 <null>
ldc.i4.0 <null>
ldelem.ref <null>
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
call System.Byte[] oMj24mm.3jiJp4Wt/5zxEwtW6G4gc.9yaHW1xqkDi3::gLo18fyWY(System.String)
stelem.ref <null>
ldloc.3 <null>
ldc.i4.3 <null>
ldloc.3 <null>
ldc.i4.2 <null>
ldelem.ref <null>
castclass System.Byte[]
call System.Byte[] oMj24mm.0jjGrkH2fW4o9::2AmeDya38dJktL(System.Byte[])
stelem.ref <null>
ldloc.3 <null>
ldloc.2 <null>
call System.Void oMj24mm.iZn0dx9E4Wfgy/7Xmgs9zD0yQ.gFi9E3esrrG2c::8ToqEg7t9xe(System.Object[],System.Int32)
nop <null>
leave.s IL_0063: nop
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.s V_5
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0063: nop
nop <null>
ret <null>
Module Name
oMj24mm
Full Name
oMj24mm
EntryPoint
System.Void oMj24mm.Zbw2f7Gqx::Xsx27Eqnz()
Scope Name
oMj24mm
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
oMj24mm
Assembly Version
4.1.21.99
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1083
Main Method
System.Void oMj24mm.Zbw2f7Gqx::Xsx27Eqnz()
Main IL Instruction Count
51
Main IL
nop <null>
nop <null>
ldc.i4.s 25
stloc.2 <null>
ldloc.2 <null>
ldc.i4.1 <null>
sub.ovf <null>
ldc.i4.1 <null>
add.ovf <null>
newarr System.Object
stloc.3 <null>
ldloc.3 <null>
ldc.i4.0 <null>
ldstr 562567.tsx
stelem.ref <null>
ldloc.3 <null>
ldc.i4.1 <null>
ldc.i4 8848948
stloc.s V_4
ldloca.s V_4
call System.String System.Int32::ToString()
stelem.ref <null>
ldloc.3 <null>
ldc.i4.2 <null>
ldloc.3 <null>
ldc.i4.0 <null>
ldelem.ref <null>
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
call System.Byte[] oMj24mm.3jiJp4Wt/5zxEwtW6G4gc.9yaHW1xqkDi3::gLo18fyWY(System.String)
stelem.ref <null>
ldloc.3 <null>
ldc.i4.3 <null>
ldloc.3 <null>
ldc.i4.2 <null>
ldelem.ref <null>
castclass System.Byte[]
call System.Byte[] oMj24mm.0jjGrkH2fW4o9::2AmeDya38dJktL(System.Byte[])
stelem.ref <null>
ldloc.3 <null>
ldloc.2 <null>
call System.Void oMj24mm.iZn0dx9E4Wfgy/7Xmgs9zD0yQ.gFi9E3esrrG2c::8ToqEg7t9xe(System.Object[],System.Int32)
nop <null>
leave.s IL_0063: nop
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.s V_5
nop <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0063: nop
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Reflective Loader
Malicious
Overlay_fef55cbd.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
AttachedParser.TokenParser
OperationalParser.HiddenParser
DetachedParser.ParserFactory
ParserEditor.ParserElement
.Net Resources
Maselatki.562567.tsx
oMj24mm.Resources.resources
ab1a64766075e4.Resources.resources
b92bf1a60
[NBF]root.Data
b92bf1a61
[NBF]root.Data
b92bf1a610
[NBF]root.Data
b92bf1a611
[NBF]root.Data
b92bf1a612
[NBF]root.Data
b92bf1a613
[NBF]root.Data
b92bf1a614
[NBF]root.Data
b92bf1a615
[NBF]root.Data
b92bf1a616
[NBF]root.Data
b92bf1a617
[NBF]root.Data
b92bf1a618
[NBF]root.Data
b92bf1a619
[NBF]root.Data
b92bf1a62
[NBF]root.Data
b92bf1a620
[NBF]root.Data
b92bf1a621
[NBF]root.Data
b92bf1a622
[NBF]root.Data
b92bf1a623
[NBF]root.Data
b92bf1a624
[NBF]root.Data
b92bf1a63
[NBF]root.Data
b92bf1a64
[NBF]root.Data
b92bf1a65
[NBF]root.Data
b92bf1a66
[NBF]root.Data
b92bf1a67
[NBF]root.Data
b92bf1a68
[NBF]root.Data
b92bf1a69
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙