Malicious
bad081341c8fb06e01a2abd0c880ce6a
PE Executable
MD5: bad081341c8fb06e01a2abd0c880ce6a
Size: 1.04 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | bad081341c8fb06e01a2abd0c880ce6a |
| Sha1 | b464795e3aa5a5f31f3620e38fc1a2b28cb847c5 |
| Sha256 | 080dfb9d893d2dd995e8fb81a4098a8d908c563e38d70a8e5bc15debcf1f065a |
| Sha384 | d5b336ff186abcd7fd844c9cdc82229d6ece645665061a306a124b1199074b13ccdbe768a2fac1a6aec06560afbb85f7 |
| Sha512 | b7e7222c0e5d2de4a4ac7719ca554c7c8841e378aaf1aa4798dd72dd70e98a54ec60fccebd6a6508ebd34563290f9765f4b6f588b6ea4a5bab912cb71789dafd |
| SSDeep | 24576:p4BAzB09Pzy4024DjyKNUR3ajtNk4+iyh2C:p4eBCe40tjy0UtWk4nC |
| TLSH | 5C25127F0CC21DA5C93F0E7A415B2CA823F08B5B561AE36B3EEC05FD9B1B6589912453 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
4 / 4
Path
pe:exe>pe:dll~T1059.007>pe:rsrc>bin
Shape
pe:exe>pe:dll>pe:rsrc>bin
malicious
4 nodes
Path
pe:exe>pe:dll~T1059.007>bin
Shape
pe:exe>pe:dll>bin
malicious
3 nodes
| Name | Value |
|---|---|
| Module Name | 2spJZ3kw |
| Full Name | 2spJZ3kw |
| EntryPoint | System.Void Pm8x9Z.ct4N8Fy::Jc7pkPs2Tj3g9A() |
| Scope Name | 2spJZ3kw |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | 2spJZ3kw |
| Assembly Version | 15.26.40.59 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 0 |
| Main Method | System.Void Pm8x9Z.ct4N8Fy::Jc7pkPs2Tj3g9A() |
| Main IL Instruction Count | 7 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | 2spJZ3kw |
| Full Name | 2spJZ3kw |
| EntryPoint | System.Void Pm8x9Z.ct4N8Fy::Jc7pkPs2Tj3g9A() |
| Scope Name | 2spJZ3kw |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | 2spJZ3kw |
| Assembly Version | 15.26.40.59 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.6 |
| Total Strings | 0 |
| Main Method | System.Void Pm8x9Z.ct4N8Fy::Jc7pkPs2Tj3g9A() |
| Main IL Instruction Count | 7 |
| Main IL | |
Malicious
No malware configuration was found at this point.
You must be signed in to view YARA rules.