Malicious
PE Executable
MD5: e4a11abf065163684f5f543b8fe06796
Size: 1.05 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
High
| MD5 | e4a11abf065163684f5f543b8fe06796 |
| Sha1 | 56e18908558f4652bac0123b9d16bbc719ed609a |
| Sha256 | 8b508de8fdef1ad8afc04161b4da7ea4dc8df8034330c2efd3a839e3ff843894 |
| Sha384 | 63451c0f77695154d336fcd0e46a5809fd93188ac848ed11f009d21208e2edac827b4452ed9b0691ade6fa80a2bd1740 |
| Sha512 | 6d2fa0ea0007abede2c0d23a93cefea9f09d73781a834055d78339ae3328bca5fa11680eed94a1d90c5c35c361737ab2cb6d7f88ad32c867db8e7623d2624662 |
| SSDeep | 24576:GTjP/2oSdvJs6/Zwvb6LqXjVe+rljawGt4KddLU5mrkS2KX3s:GTb/2oSRMLjVe+rIptDdl2S2Kn |
| TLSH | 5B250208221BDD01C1A21EB019F1E7F406B49E84E622D757DEEA7CEBB93B3952D953C1 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
4 / 4
Path
pe:exe>pe:rsrc>img
Shape
pe:exe>pe:rsrc>img
malicious
3 nodes
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
| Name | Value |
|---|---|
| Module Name | ggOI.exe |
| Full Name | ggOI.exe |
| EntryPoint | System.Void L9.pJ::UA() |
| Scope Name | ggOI.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | ggOI |
| Assembly Version | 8.6.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 149 |
| Main Method | System.Void L9.pJ::UA() |
| Main IL Instruction Count | 16 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: ggOI.pdb |
| Module Name | ggOI.exe |
| Full Name | ggOI.exe |
| EntryPoint | System.Void L9.pJ::UA() |
| Scope Name | ggOI.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | ggOI |
| Assembly Version | 8.6.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 149 |
| Main Method | System.Void L9.pJ::UA() |
| Main IL Instruction Count | 16 |
| Main IL | |