Malicious
Malicious

e96fae9165fec1ef367a489ef9482718

PE Executable
MD5: e96fae9165fec1ef367a489ef9482718
Size: 320 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 e96fae9165fec1ef367a489ef9482718
Sha1 025929ee079ce5faf9314f94259b28b32a7cf52f
Sha256 a119dd7bc00bdffea94ca4da1bcdffc6592409cd3f0ea81f48d62b26481cc7c9
Sha384 3188a7e6f62792c4156bf01ce8c4f1a5b6efa616263c2e287a55f8c32129a1f421e06d6a529503979a1159d6673e5bdd
Sha512 e386d43213da3d7111ad2582c3eef6a4e179d5df2baacb17238766cb4c33f59faa50d17ab953d195495448952aedfb5ad892176bdfed5239137e85abac88e9a8
SSDeep 6144:KNGrB1QeMRPWOJ884uYUsUMACCKLAxub82gFv:8CYUOmIYdUMTHbXg
TLSH D764AE4676E2DF11D39C263690A3482463B5E7C332B3F74E6F9911726C062F45EA63E2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
ipAwVe0sq2PS46Onpf.I2UuQhHPIcAuMWv4tf
CLOX5iPmpV8sVr0eyG.Ir1thMpYaiFJwH6fBD
pALUCGIFBWdnaUShhE.SPwPHx5D82MhQ1ZefL
ClassLibrary2.g.resources
DcelA3rpDagom0Eo2K.Pn3lO1ypcBbT6hy7GJ
7CXNLWgXhrKh0bmDeJ.0DB2j7tcCV7gl1MDqt
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll>pe:rsrc>bin
Shape pe:dll>pe:rsrc>bin
malicious 3 nodes
Path pe:dll>bin
Shape pe:dll>bin
malicious 2 nodes
Name Value
Module Name
ClassLibrary2.dll
Full Name
ClassLibrary2.dll
Scope Name
ClassLibrary2.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ClassLibrary2
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
48
Main Method
Not found or no body
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: ClassLibrary2.pdb
Module Name
ClassLibrary2.dll
Full Name
ClassLibrary2.dll
Scope Name
ClassLibrary2.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ClassLibrary2
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
48
Main Method
Not found or no body
.Net Resources
ipAwVe0sq2PS46Onpf.I2UuQhHPIcAuMWv4tf
CLOX5iPmpV8sVr0eyG.Ir1thMpYaiFJwH6fBD
pALUCGIFBWdnaUShhE.SPwPHx5D82MhQ1ZefL
ClassLibrary2.g.resources
DcelA3rpDagom0Eo2K.Pn3lO1ypcBbT6hy7GJ
7CXNLWgXhrKh0bmDeJ.0DB2j7tcCV7gl1MDqt
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙