Malicious
Malicious

ba425803971bbd612fab8d127f940623

PE Executable
MD5: ba425803971bbd612fab8d127f940623
Size: 1.17 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 ba425803971bbd612fab8d127f940623
Sha1 c641df031f54df0ef3625219aca86b0c3972d546
Sha256 4878f4605acdf2ba1cd57072d13d1b19712e914799df5132f5397a550dca3427
Sha384 e82ad984bc8adc145ac161d875742ab0574eb3fb37f1be335fe03af05b47971b9f5cd70c1cfb3b6abdaee3fb1b572621
Sha512 89ddb881dbd2976613da5f0b818d8b82eef96d922bc55cfc827086beba139b018efaa834c2730481b6caa294ea565de80ea7aec564cd4783f1ded447dc76f3de
SSDeep 24576:5u1jP/2oSdvpiUdvYfxwOGKHVk9f77F5QCAhODJ/kCtR5P0rJNcl+:5u1b/2oSZg6OGK1C7R5QCIr+
TLSH 0E4502086357DD02D2C60FB05DA1E3B45AB48F849912C7039EEE3DEBB97B3562E442D6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
mE1.dEO.resources
$this.Icon
[NBF]root.IconData
Pro
[NBF]root.Data
backgroundWorker1.TrayLocation
aEa.YE5.resources
zEo.DE0.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
NeuralLinkDataMiner.Properties.Resources.resources
FFOZ
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: lmdV.pdb
Module Name
lmdV.exe
Full Name
lmdV.exe
EntryPoint
System.Void w1.IO::FK()
Scope Name
lmdV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lmdV
Assembly Version
8.6.4.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
149
Main Method
System.Void w1.IO::FK()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
call System.Void knd.anW::AQA()
br IL_000F: nop
nop <null>
newobj System.Void mE1.dEO::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001F: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void knd.anW::AQA()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0021: nop
Module Name
lmdV.exe
Full Name
lmdV.exe
EntryPoint
System.Void w1.IO::FK()
Scope Name
lmdV.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lmdV
Assembly Version
8.6.4.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
149
Main Method
System.Void w1.IO::FK()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
call System.Void knd.anW::AQA()
br IL_000F: nop
nop <null>
newobj System.Void mE1.dEO::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001F: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void knd.anW::AQA()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0021: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
mE1.dEO.resources
$this.Icon
[NBF]root.IconData
Pro
[NBF]root.Data
backgroundWorker1.TrayLocation
aEa.YE5.resources
zEo.DE0.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
NeuralLinkDataMiner.Properties.Resources.resources
FFOZ
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙