Malicious
Malicious

eed11bfc65801c82e95028c89f63e711

PE Executable
MD5: eed11bfc65801c82e95028c89f63e711
Size: 1.79 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 eed11bfc65801c82e95028c89f63e711
Sha1 a0c08231bd393f8c1302defb6307fe240b21cbc7
Sha256 65528e4223570e3286739396fa918a431b4d6fd9860dd9d913a0b2adaf1ab3be
Sha384 5f1469932888eee7fbf525a53c6ebef246cd0f93b321bbdbbecb883dc0c7a9ab240e676b0694e396b023909e71aa00f6
Sha512 8103c626ea59acb2897244a4cdd625de1269d8aaee0801fd382e19d6689237c7ad2fc37fea375a6558d6052cfc8b6df9680f02210bf5110ad17a1e245f1a1a36
SSDeep 24576:Og9kBap6vkIztc8RaZUrvXBRf/LtdI2LO9NEJqrwUNqHzW0NzaDn:OmsVz28RaZ4nxdRsyw7NqTWa
TLSH 6485F17C3123ED8ED6428A358950DE7882206E594616E213F6D73FAF7D3E18F9D142A3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
.Net Resources
YgBe.g.resources
SoftwareRenderer.Properties.Resources.resources
TK
[NBF]root.Data
IfWr
[NBF]root.Data
[NBF]root.Data-preview.png
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Module Name
YgBe.exe
Full Name
YgBe.exe
EntryPoint
System.Void r4.NI::op()
Scope Name
YgBe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YgBe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
0
Main Method
System.Void r4.NI::op()
Main IL Instruction Count
40
Main IL
br.s IL_004C: call System.Void r4.NI::‭‌‮‎‭‌‫‏‎‫‎‌​‌‬‏​‎‌‏‮()
ldc.i4 1055164632
ldc.i4 524723467
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.s 9
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_009F: br.s IL_006F
ldloc.0 <null>
ldc.i4 1648410785
mul <null>
ldc.i4 350898910
xor <null>
br.s IL_0007: ldc.i4 524723467
call System.Void r4.NI::‭‌‮‎‭‌‫‏‎‫‎‌​‌‬‏​‎‌‏‮()
ldc.i4 1616018663
br.s IL_0007: ldc.i4 524723467
ldloc.0 <null>
ldc.i4 -1584295333
mul <null>
ldc.i4 1574444645
xor <null>
br.s IL_0007: ldc.i4 524723467
ret <null>
ldc.i4 346270449
br.s IL_0007: ldc.i4 524723467
ldc.i4.0 <null>
call System.Void r4.NI::‏‪‮‫‮‏‌‬‬‪‫‫‬‭‪‏‏‍​​​‫‮‬‎‮(System.Boolean)
ldc.i4 346270449
br.s IL_0007: ldc.i4 524723467
newobj System.Void Xso.VsF::.ctor()
call System.Void r4.NI::‏‍​‪‪‏‭‎‭‮‭‌‪‌‏‏‎‬‍‫‏‬‮‫‮​‎‮(System.Windows.Forms.Form)
ldc.i4 1607741034
br IL_0007: ldc.i4 524723467
call System.Void Ned.VeC::z00()
ldc.i4 1977817208
br IL_0007: ldc.i4 524723467
br.s IL_006F: ldc.i4.0
Info
PE Detect: PeReader OK (file layout)
Module Name
YgBe.exe
Full Name
YgBe.exe
EntryPoint
System.Void r4.NI::op()
Scope Name
YgBe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
YgBe
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
0
Main Method
System.Void r4.NI::op()
Main IL Instruction Count
40
Main IL
br.s IL_004C: call System.Void r4.NI::‭‌‮‎‭‌‫‏‎‫‎‌​‌‬‏​‎‌‏‮()
ldc.i4 1055164632
ldc.i4 524723467
xor <null>
dup <null>
stloc.0 <null>
ldc.i4.s 9
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br.s IL_009F: br.s IL_006F
ldloc.0 <null>
ldc.i4 1648410785
mul <null>
ldc.i4 350898910
xor <null>
br.s IL_0007: ldc.i4 524723467
call System.Void r4.NI::‭‌‮‎‭‌‫‏‎‫‎‌​‌‬‏​‎‌‏‮()
ldc.i4 1616018663
br.s IL_0007: ldc.i4 524723467
ldloc.0 <null>
ldc.i4 -1584295333
mul <null>
ldc.i4 1574444645
xor <null>
br.s IL_0007: ldc.i4 524723467
ret <null>
ldc.i4 346270449
br.s IL_0007: ldc.i4 524723467
ldc.i4.0 <null>
call System.Void r4.NI::‏‪‮‫‮‏‌‬‬‪‫‫‬‭‪‏‏‍​​​‫‮‬‎‮(System.Boolean)
ldc.i4 346270449
br.s IL_0007: ldc.i4 524723467
newobj System.Void Xso.VsF::.ctor()
call System.Void r4.NI::‏‍​‪‪‏‭‎‭‮‭‌‪‌‏‏‎‬‍‫‏‬‮‫‮​‎‮(System.Windows.Forms.Form)
ldc.i4 1607741034
br IL_0007: ldc.i4 524723467
call System.Void Ned.VeC::z00()
ldc.i4 1977817208
br IL_0007: ldc.i4 524723467
br.s IL_006F: ldc.i4.0
.Net Resources
YgBe.g.resources
SoftwareRenderer.Properties.Resources.resources
TK
[NBF]root.Data
IfWr
[NBF]root.Data
[NBF]root.Data-preview.png
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙