Malicious
Malicious

PE Executable
MD5: f56175411b1f3f1d0c22745b2b45fedd
Size: 3.79 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 f56175411b1f3f1d0c22745b2b45fedd
Sha1 a901aa9eda35bc64f3cb0a76da45814e5255bea3
Sha256 a1638a6e9d55a06c4fe43c738950b84a01f43f7883f1bd06bb2cbb60f02c87d2
Sha384 62503802998783efbba1e0abadd0537774f5cc8dd43f4af7d12bc13044dd22b76c470dd8225cc88b53a64a139fea5629
Sha512 174a958f8aeb91836bb355402f4b9ccf6fc622385219e0d7416dd7874323ccaa5a8caa1ff7ab3b799102653137afecbbba958227fc06d22d02183686c5af863b
SSDeep 49152:hYNq+q13wXoeAkmNoZBMZsCcdAxYFJNH7rOQW0O6s2HA1dajUynthRhHtjsuIu:hYNqjP2EQW76s4A14Uynth/tjsw
TLSH A4066C1BFE9E6992C281B776C6F70D101361E6436313D32B364BA3FAEC4B7662901197
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Rbxza.Properties.Resources.resources
Erbull
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
newStub.exe
Full Name
newStub.exe
EntryPoint
System.Void SteamKit2.Notifications.NotifierRunner::AlertConfigurableNotifier()
Scope Name
newStub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
newStub
Assembly Version
1.0.5214.24172
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1291
Main Method
System.Void SteamKit2.Notifications.NotifierRunner::AlertConfigurableNotifier()
Main IL Instruction Count
18
Main IL
ldc.i4 1
stloc V_0
br IL_000E: ldloc V_0
ldloc V_0
switch dnlib.DotNet.Emit.Instruction[]
br IL_0024: ret
ret <null>
newobj System.Void newStub.Core.Engines.PortableEngine::.ctor()
call System.Byte[] newStub.Core.Engines.PortableEngine::StopEngine()
call System.Byte[] newStub.Messaging.SimpleSubscriber::ListenScalableSubscriber(System.Object)
call System.Void SteamKit2.Programming.SortedFunction::ImplementFlexibleFunction(System.Object)
ldc.i4 0
ldsfld <Module>{7cd11c8f-c5cc-4119-b60a-4085bc7e0024} <Module>{7cd11c8f-c5cc-4119-b60a-4085bc7e0024}::m_26551412e1cc4178b52f0c1df3b2e4a7
ldfld System.Int32 <Module>{7cd11c8f-c5cc-4119-b60a-4085bc7e0024}::m_9c4c7e3b63ef42a6af9e93317d644de1
brfalse IL_0012: switch(IL_0024,IL_0025)
pop <null>
ldc.i4 0
br IL_0012: switch(IL_0024,IL_0025)
Module Name
newStub.exe
Full Name
newStub.exe
EntryPoint
System.Void SteamKit2.Notifications.NotifierRunner::AlertConfigurableNotifier()
Scope Name
newStub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
newStub
Assembly Version
1.0.5214.24172
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
1291
Main Method
System.Void SteamKit2.Notifications.NotifierRunner::AlertConfigurableNotifier()
Main IL Instruction Count
18
Main IL
ldc.i4 1
stloc V_0
br IL_000E: ldloc V_0
ldloc V_0
switch dnlib.DotNet.Emit.Instruction[]
br IL_0024: ret
ret <null>
newobj System.Void newStub.Core.Engines.PortableEngine::.ctor()
call System.Byte[] newStub.Core.Engines.PortableEngine::StopEngine()
call System.Byte[] newStub.Messaging.SimpleSubscriber::ListenScalableSubscriber(System.Object)
call System.Void SteamKit2.Programming.SortedFunction::ImplementFlexibleFunction(System.Object)
ldc.i4 0
ldsfld <Module>{7cd11c8f-c5cc-4119-b60a-4085bc7e0024} <Module>{7cd11c8f-c5cc-4119-b60a-4085bc7e0024}::m_26551412e1cc4178b52f0c1df3b2e4a7
ldfld System.Int32 <Module>{7cd11c8f-c5cc-4119-b60a-4085bc7e0024}::m_9c4c7e3b63ef42a6af9e93317d644de1
brfalse IL_0012: switch(IL_0024,IL_0025)
pop <null>
ldc.i4 0
br IL_0012: switch(IL_0024,IL_0025)
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Rbxza.Properties.Resources.resources
Erbull
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙