Malicious
Malicious

ee4eb2afd293e11b358929d2ffc5a311

PE Executable
MD5: ee4eb2afd293e11b358929d2ffc5a311
Size: 1.32 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 ee4eb2afd293e11b358929d2ffc5a311
Sha1 4276e56ce6490f8ef5d8834f7f6c7fafb33ca6c8
Sha256 4a9a4282a7c02191cfdcc480e7af5fc5619be8902cae717cda731dd32cf493c5
Sha384 b3de76a02d814fc02df23183899145bb3a8551d676330cd5be689ee4cc12de4b1459243344ffa462299bc754dde83383
Sha512 386e7c261d421d077da4c3071ccdb6c8f94ad3743314b9a100a09e49d408df28ac7f37f7a16791f17006a41c32860264602c9e4990ee309d95c3919731491698
SSDeep 24576:FsVi1hhj5lkf7v7kn/OtVQrmhS+tU6WDS7WnyjOZxW5GxPSZ:4mh7Gfrms+rmQ+66k7yKHgGxPS
TLSH FA55F1959316C807C6901AB4C9B1FBB512786FF8E807C353FAE67DEBB9283463845253
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
u5.Jy.resources
vCn.FCh.resources
$this.Icon
[NBF]root.IconData
oCd.UCU.resources
$this.Icon
[NBF]root.IconData
contextMenu.TrayLocation
Bi
[NBF]root.Data
notifyIcon.Icon
[NBF]root.IconData
timer.TrayLocation
notifyIcon.TrayLocation
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Clock.Properties.Resources.resources
UvPu
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Name Value
Module Name
KlZf.exe
Full Name
KlZf.exe
EntryPoint
System.Void pZE.YZ2::WZt()
Scope Name
KlZf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KlZf
Assembly Version
10.0.26100.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Info
PE Detect: PeReader OK (file layout)
Total Strings
182
Main Method
System.Void pZE.YZ2::WZt()
Main IL Instruction Count
15
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0017: nop
nop <null>
ret <null>
call System.Void yu5.huy::M3l()
br IL_0023: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_000D: call System.Void yu5.huy::M3l()
nop <null>
newobj System.Void oCd.UCU::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000B: nop
Module Name
KlZf.exe
Full Name
KlZf.exe
EntryPoint
System.Void pZE.YZ2::WZt()
Scope Name
KlZf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
KlZf
Assembly Version
10.0.26100.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
182
Main Method
System.Void pZE.YZ2::WZt()
Main IL Instruction Count
15
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0017: nop
nop <null>
ret <null>
call System.Void yu5.huy::M3l()
br IL_0023: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_000D: call System.Void yu5.huy::M3l()
nop <null>
newobj System.Void oCd.UCU::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000B: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
u5.Jy.resources
vCn.FCh.resources
$this.Icon
[NBF]root.IconData
oCd.UCU.resources
$this.Icon
[NBF]root.IconData
contextMenu.TrayLocation
Bi
[NBF]root.Data
notifyIcon.Icon
[NBF]root.IconData
timer.TrayLocation
notifyIcon.TrayLocation
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Clock.Properties.Resources.resources
UvPu
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙