Malicious
PE Executable
MD5: c91922ec7d30c7c1d9c9a93f6859e788
Size: 245.25 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | c91922ec7d30c7c1d9c9a93f6859e788 |
| Sha1 | feb97dadb4d09226f6a42a68c50992e0958db5e1 |
| Sha256 | 8c99f17e2927d4a33c0bebea8465c3bac494a4796fed56cb172cbd8920b15a8a |
| Sha384 | b0bb0ac40ebbe8f137bed24a42ea60146566f7ad3a79d2891be0f822373ba44801fe4c0b226938e21c05188f2bd65271 |
| Sha512 | d0f2a2d66bfae9fdb4380b435d977fbec1b74430894735b7cfc8fc2938aaf8a4d2d53bf52c570bb9027ae2cdd323651bde3ebfdf48907570e0421a5e570b8d73 |
| SSDeep | 3072:rJXCyKayjlejyAWb002XTHo9rG8KaG5jnThMSEufzz:1CyKayZuSIsq8KaWTa |
| TLSH | 313400027F88EB15E1A93E3782EF6C2453B2B4C71633C60B6F49AF5524516826C7E72D |
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
| Name | Value |
|---|---|
| Module Name | 8N57q4CivJ |
| Full Name | 8N57q4CivJ |
| EntryPoint | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Scope Name | 8N57q4CivJ |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | f45b853c-c9d3-495e-9acb-d41a4a90029f |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 1093 |
| Main Method | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Main IL Instruction Count | 62 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | 8N57q4CivJ |
| Full Name | 8N57q4CivJ |
| EntryPoint | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Scope Name | 8N57q4CivJ |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | f45b853c-c9d3-495e-9acb-d41a4a90029f |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 1093 |
| Main Method | System.Void HezT.lgBKovGgL::CsvxrnfLmFv() |
| Main IL Instruction Count | 62 |
| Main IL | |