Malicious
Malicious

agentSessionBroker.exe

PE Executable
MD5: d05a543ff3a91d33849184035d351e3c
Size: 1.06 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 d05a543ff3a91d33849184035d351e3c
Sha1 e79c4fff547be2e197a2bdf93e4ca6da6cad0824
Sha256 274299a4573569f78b72287a2635f3997ee909897e21b87216b868596dbe4a17
Sha384 02c929a45da125b7e7d13ceb63f4847ead0de3abd699866015bb87860ea75e0f3722d09153bcee8fceecbf1d2016c344
Sha512 e93de81d6cf26e30ce3ba1b6f15cf133a25bc38573877a5697fad212a26a7c8a0589c5ccb46e35910093b4587ee83eff3bb85871195736c0ac8e89c933aa5ea8
SSDeep 24576:/VtG/LCSO0ZAruazXEOqf9ff2HPFknukWvgUcB:/VtG2BblOIdknuTvgUc
TLSH AA3528027E44CA11F0191233C2EF454887F4A9516BA6E32B7DBA376E58173A73C4D9EB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
uRkrRwgnOqY16XJes8.WiaBtHPJ9lXvH0sk6N
7p6hHk2ua5QUKn261g.a020SQISdlGjCdTItY
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Ofabu5sPx8nnekN33ga9Ox9y1GY3ZLGNzPZ
Full Name
Ofabu5sPx8nnekN33ga9Ox9y1GY3ZLGNzPZ
EntryPoint
System.Void ehOqTDWusuKksekvtcq.u1WA3IWiNHPoxIxI2iW::lh0cFT7dN6()
Scope Name
Ofabu5sPx8nnekN33ga9Ox9y1GY3ZLGNzPZ
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
uaKRnxPDBdWLfFo8b8
Assembly Version
5.4.5.6
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void ehOqTDWusuKksekvtcq.u1WA3IWiNHPoxIxI2iW::lh0cFT7dN6()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void ATRF5xc6lABC0dethxu.Y7B9fucHZFUZVRSAAMh::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object ehOqTDWusuKksekvtcq.u1WA3IWiNHPoxIxI2iW::a2VcQBgZ6J
callvirt System.Void EJxSADWH3NKCrLtMPX7.uRXhlTWqtdfLqSxPIyu::CJekOaFplV()
nop <null>
ret <null>
Module Name
Ofabu5sPx8nnekN33ga9Ox9y1GY3ZLGNzPZ
Full Name
Ofabu5sPx8nnekN33ga9Ox9y1GY3ZLGNzPZ
EntryPoint
System.Void ehOqTDWusuKksekvtcq.u1WA3IWiNHPoxIxI2iW::lh0cFT7dN6()
Scope Name
Ofabu5sPx8nnekN33ga9Ox9y1GY3ZLGNzPZ
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
uaKRnxPDBdWLfFo8b8
Assembly Version
5.4.5.6
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
63
Main Method
System.Void ehOqTDWusuKksekvtcq.u1WA3IWiNHPoxIxI2iW::lh0cFT7dN6()
Main IL Instruction Count
14
Main IL
br.s IL_000B: ldc.i4.0
call <null>
ldnull <null>
ldc.i4.0 <null>
ldelem.ref <null>
pop <null>
ldc.i4.0 <null>
brtrue.s IL_0007: ldnull
call System.Void ATRF5xc6lABC0dethxu.Y7B9fucHZFUZVRSAAMh::kLjw4iIsCLsZtxc4lksN0j()
nop <null>
ldsfld System.Object ehOqTDWusuKksekvtcq.u1WA3IWiNHPoxIxI2iW::a2VcQBgZ6J
callvirt System.Void EJxSADWH3NKCrLtMPX7.uRXhlTWqtdfLqSxPIyu::CJekOaFplV()
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
uRkrRwgnOqY16XJes8.WiaBtHPJ9lXvH0sk6N
7p6hHk2ua5QUKn261g.a020SQISdlGjCdTItY
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙