Suspicious
Suspect

da4dc2203770bb12d6a2d5b38a5880a0

PE Executable
MD5: da4dc2203770bb12d6a2d5b38a5880a0
Size: 3.23 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 da4dc2203770bb12d6a2d5b38a5880a0
Sha1 66daed03974ace9055154d3e818bd5ef957ef651
Sha256 92f8f069c032422eb6048ce1a648bd140dab9d3cfca5c855e2b56e1ac6f1cc7b
Sha384 05e14cb8208933979b3095649db05952432d972808777d00bee797e75e8dedca1fe864ceb00fcb4ce9c79e686808ebfc
Sha512 3bc8d2d19be258ced3a13e41759ebf0556cd230d407b91ce7a6005ebec830dfddb77fd8a7edeeceb2d75a25aebcddc2ce5cef5dd4bc164024236624435886715
SSDeep 98304:0xPvhSPnC38hCUL7Ig5Us7gYyE35CXbbVtY8K04:0Pv4PEeIg5xgYR3EXbZm8Z
TLSH D5E533F9937653CCDB2AA2353FC3F9542305C189BE9149D86174B250EB394E6FEC6228
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
wkuiupme.Resources
mrshtclient.exe
pulse_launcher.exe
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
pulse_launchеr.exe
Full Name
pulse_launchеr.exe
EntryPoint
System.Void Program::Main()
Scope Name
pulse_launchеr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pulse_launchеr
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
10
Main Method
System.Void Program::Main()
Main IL Instruction Count
10
Main IL
ldc.i4 2000
call System.Void System.Threading.Thread::Sleep(System.Int32)
call System.Boolean Program::CreateMutex()
brtrue.s IL_001B: ldnull
call System.Int32 System.Environment::get_ExitCode()
call System.Void System.Environment::Exit(System.Int32)
ldnull <null>
call System.Object Program::WorkF(System.Object)
pop <null>
ret <null>
Module Name
pulse_launchеr.exe
Full Name
pulse_launchеr.exe
EntryPoint
System.Void Program::Main()
Scope Name
pulse_launchеr.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
pulse_launchеr
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
10
Main Method
System.Void Program::Main()
Main IL Instruction Count
10
Main IL
ldc.i4 2000
call System.Void System.Threading.Thread::Sleep(System.Int32)
call System.Boolean Program::CreateMutex()
brtrue.s IL_001B: ldnull
call System.Int32 System.Environment::get_ExitCode()
call System.Void System.Environment::Exit(System.Int32)
ldnull <null>
call System.Object Program::WorkF(System.Object)
pop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
wkuiupme.Resources
mrshtclient.exe
pulse_launcher.exe
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙