Malicious
Malicious

bc88ad0b4dfbba15fbe4bd94e20f6a46

PE Executable
MD5: bc88ad0b4dfbba15fbe4bd94e20f6a46
Size: 93.7 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 bc88ad0b4dfbba15fbe4bd94e20f6a46
Sha1 2c4a02971ec81b6ee6095dbd604bca1b24c70182
Sha256 5ab9730d806b865f8f8dc52ae90ee4280dc3e54a23ae66226a9b7228e7b6c572
Sha384 ee5ea40dc4187c19f46c70847f03bd8157720e1774de961955eb8e01937927762c9903db9957e070c45d4d87322299ca
Sha512 a864003664330d3ad854fea7e8d753d5d82c76c9e89dca140dd2833dc22bbf24ca00f5ecba6a2db302cfcd559470a3a5a554ef1b3d5cfb02a91233f5a94ca921
SSDeep 1536:PmhwZC18Dq21Kth+hThN/UP/UJS/UJ5/UJpQMhVVYpLN7FMRFZPp4nw:MwZC18DqPth+hThN/UP/UJS/UJ5/UJpJ
TLSH CE93080937EC9814EABF8572E67151200B7ABC554936D21D1BD8B4EE2B3BA8085C7BD3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CloudServices.Resources.resources
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
CloudServices.exe
Full Name
CloudServices.exe
EntryPoint
System.Void CloudServices.UltraSpeed::Main()
Scope Name
CloudServices.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CloudServices
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
787
Main Method
System.Void CloudServices.UltraSpeed::Main()
Main IL Instruction Count
18
Main IL
nop <null>
call System.Void CloudServices.UltraSpeed::isUserExpired()
nop <null>
call System.Void CloudServices.UltraSpeed::DisableWD()
nop <null>
call System.Void CloudServices.UltraSpeed::Taskmgr_Disabler()
nop <null>
call System.Void CloudServices.UltraSpeed::CMD_Disabler()
nop <null>
call System.Void CloudServices.UltraSpeed::Registeries_Disabler()
nop <null>
call System.Void CloudServices.UltraSpeed::Start()
nop <null>
call System.Void CloudServices.UltraSpeed::StartView()
nop <null>
call System.Void System.Windows.Forms.Application::Run()
nop <null>
ret <null>
Module Name
CloudServices.exe
Full Name
CloudServices.exe
EntryPoint
System.Void CloudServices.UltraSpeed::Main()
Scope Name
CloudServices.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
CloudServices
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
787
Main Method
System.Void CloudServices.UltraSpeed::Main()
Main IL Instruction Count
18
Main IL
nop <null>
call System.Void CloudServices.UltraSpeed::isUserExpired()
nop <null>
call System.Void CloudServices.UltraSpeed::DisableWD()
nop <null>
call System.Void CloudServices.UltraSpeed::Taskmgr_Disabler()
nop <null>
call System.Void CloudServices.UltraSpeed::CMD_Disabler()
nop <null>
call System.Void CloudServices.UltraSpeed::Registeries_Disabler()
nop <null>
call System.Void CloudServices.UltraSpeed::Start()
nop <null>
call System.Void CloudServices.UltraSpeed::StartView()
nop <null>
call System.Void System.Windows.Forms.Application::Run()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CloudServices.Resources.resources
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙