Malicious
Malicious

d1b18404eb25fb66030bd1e426a639c5

PE Executable
MD5: d1b18404eb25fb66030bd1e426a639c5
Size: 909.31 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 d1b18404eb25fb66030bd1e426a639c5
Sha1 bfa6c39cdca285754eb02370e2da26645b0d7709
Sha256 024d5533d9cd346418c7780706410fca28f88e33291e8ca6b382299dfea043da
Sha384 6358c6dcf6f251cb6fae940b436726abe8866ba5d503892e4069e9fd61eb66153f942db94f454f46b93a9baaeb54eb36
Sha512 3736a9b85e690cb4ef0752ac16e25e3e03ce948ec44130ceb9e248a030947d4e0aeb220227a64511ea1b9acaf73af8c7256c47e0b6c40b57adb22189a6775a82
SSDeep 24576:VIKX8Qu5wUEwgvmEkTPYZvBrvbDk8h4Uj2Bx:VIfQufE9vm/YZZvQ8hj
TLSH 7115AEAA39DEDC2AE0760EB4C4A1F2F203B49D91E621C207CAD57DD77931F81568274B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
qO.a9.resources
uJ2.HJf.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
AlpinePasture.Properties.Resources.resources
KL
[NBF]root.Data
gRsR
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
ycla.exe
Full Name
ycla.exe
EntryPoint
System.Void wSc.KSd::zSx()
Scope Name
ycla.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ycla
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
741
Main Method
System.Void wSc.KSd::zSx()
Main IL Instruction Count
19
Main IL
br IL_003C: nop
call System.Void Oar.oaQ::lw0()
br IL_0020: nop
ldsfld qO.a9 wSc.KSd::EaF
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001E: nop
nop <null>
ret <null>
nop <null>
newobj System.Void qO.a9::.ctor()
stsfld qO.a9 wSc.KSd::EaF
br IL_000F: ldsfld qO.a9 wSc.KSd::EaF
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void Oar.oaQ::lw0()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0030: nop
Module Name
ycla.exe
Full Name
ycla.exe
EntryPoint
System.Void wSc.KSd::zSx()
Scope Name
ycla.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ycla
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
741
Main Method
System.Void wSc.KSd::zSx()
Main IL Instruction Count
19
Main IL
br IL_003C: nop
call System.Void Oar.oaQ::lw0()
br IL_0020: nop
ldsfld qO.a9 wSc.KSd::EaF
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001E: nop
nop <null>
ret <null>
nop <null>
newobj System.Void qO.a9::.ctor()
stsfld qO.a9 wSc.KSd::EaF
br IL_000F: ldsfld qO.a9 wSc.KSd::EaF
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void Oar.oaQ::lw0()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0030: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
qO.a9.resources
uJ2.HJf.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
AlpinePasture.Properties.Resources.resources
KL
[NBF]root.Data
gRsR
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙