Malicious
Malicious

bad081341c8fb06e01a2abd0c880ce6a

Share on LinkedIn
Print
PE Executable
MD5: bad081341c8fb06e01a2abd0c880ce6a
Size: 1.04 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 bad081341c8fb06e01a2abd0c880ce6a
Sha1 b464795e3aa5a5f31f3620e38fc1a2b28cb847c5
Sha256 080dfb9d893d2dd995e8fb81a4098a8d908c563e38d70a8e5bc15debcf1f065a
Sha384 d5b336ff186abcd7fd844c9cdc82229d6ece645665061a306a124b1199074b13ccdbe768a2fac1a6aec06560afbb85f7
Sha512 b7e7222c0e5d2de4a4ac7719ca554c7c8841e378aaf1aa4798dd72dd70e98a54ec60fccebd6a6508ebd34563290f9765f4b6f588b6ea4a5bab912cb71789dafd
SSDeep 24576:p4BAzB09Pzy4024DjyKNUR3ajtNk4+iyh2C:p4eBCe40tjy0UtWk4nC
TLSH 5C25127F0CC21DA5C93F0E7A415B2CA823F08B5B561AE36B3EEC05FD9B1B6589912453
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Reflective Loader
Malicious
.Net Resources
CollectorTracer.AttributeTask
DistributorTask.VisitorTask
SimpleTask.TaskFormatter
TaskConfiguration.AuthenticatorTask
Overlay_7940c33a.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Gontoba.kelaixja.aab
2spJZ3kw.Resources.resources
e73b1863b2f9d0.Resources.resources
84e46e570
[NBF]root.Data
84e46e571
[NBF]root.Data
84e46e5710
[NBF]root.Data
84e46e5711
[NBF]root.Data
84e46e5712
[NBF]root.Data
84e46e5713
[NBF]root.Data
84e46e5714
[NBF]root.Data
84e46e5715
[NBF]root.Data
84e46e5716
[NBF]root.Data
84e46e5717
[NBF]root.Data
84e46e5718
[NBF]root.Data
84e46e5719
[NBF]root.Data
84e46e572
[NBF]root.Data
84e46e5720
[NBF]root.Data
84e46e5721
[NBF]root.Data
84e46e5722
[NBF]root.Data
84e46e5723
[NBF]root.Data
84e46e5724
[NBF]root.Data
84e46e573
[NBF]root.Data
84e46e574
[NBF]root.Data
84e46e575
[NBF]root.Data
84e46e576
[NBF]root.Data
84e46e577
[NBF]root.Data
84e46e578
[NBF]root.Data
84e46e579
[NBF]root.Data
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path pe:exe>pe:dll~T1059.007>pe:rsrc>bin
Shape pe:exe>pe:dll>pe:rsrc>bin
malicious 4 nodes
Path pe:exe>pe:dll~T1059.007>bin
Shape pe:exe>pe:dll>bin
malicious 3 nodes
Name Value
Module Name
2spJZ3kw
Full Name
2spJZ3kw
EntryPoint
System.Void Pm8x9Z.ct4N8Fy::Jc7pkPs2Tj3g9A()
Scope Name
2spJZ3kw
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
2spJZ3kw
Assembly Version
15.26.40.59
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void Pm8x9Z.ct4N8Fy::Jc7pkPs2Tj3g9A()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void Ajb3s2Pp.2ZwoHf5kq8F_::.ctor()
stloc.1 <null>
ret <null>
ldtoken System.Void Pm8x9Z.ct4N8Fy::Jc7pkPs2Tj3g9A()
pop <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
2spJZ3kw
Full Name
2spJZ3kw
EntryPoint
System.Void Pm8x9Z.ct4N8Fy::Jc7pkPs2Tj3g9A()
Scope Name
2spJZ3kw
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
2spJZ3kw
Assembly Version
15.26.40.59
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void Pm8x9Z.ct4N8Fy::Jc7pkPs2Tj3g9A()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void Ajb3s2Pp.2ZwoHf5kq8F_::.ctor()
stloc.1 <null>
ret <null>
ldtoken System.Void Pm8x9Z.ct4N8Fy::Jc7pkPs2Tj3g9A()
pop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙