Malicious
Malicious

f6cbdbd16d7723f9598b910f03ba8fc5

Share on LinkedIn
Print
PE Executable
MD5: f6cbdbd16d7723f9598b910f03ba8fc5
Size: 1.93 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 f6cbdbd16d7723f9598b910f03ba8fc5
Sha1 86f541df56a8086da2e17b1790819e4137a698c9
Sha256 2423704f01108fc081ac5257cc60ed6ca266c3958c721cf091f98a6c103813df
Sha384 0ae2393a1946f45f7f9ee58e0795d08896ce0b1bedfffb6314840a015d60cab0fa4f78aac1c614a079681ffa334a1f76
Sha512 304dbf47d9ec222640cd81818bdc1c63c5787c7590decfad322f8671f1be7dc8a3b6a2895c1835473b20f07ae375aca3314dcbe83c67029c3cf29c30f21c37b2
SSDeep 24576:/iIzB09Pzy4024DjyKNUlwPHL+e4+IgM88JqKoH7tx4GVMW3M2QZUYZ4dczA:/ioBCe40tjy0UCS3LZo7D4GxzQhZwuA
TLSH EC9501F2AB808864C82B4A794436D9A36173A60E9D6CCB0E3DD6BF1F7D323474517897
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
Gontoba.kelaixja.aab
eg9Qx1HsMna8nT.Resources.resources
09ea8bcc253c46.Resources.resources
5aff1dd20
[NBF]root.Data
5aff1dd21
[NBF]root.Data
5aff1dd210
[NBF]root.Data
5aff1dd211
[NBF]root.Data
5aff1dd212
[NBF]root.Data
5aff1dd213
[NBF]root.Data
5aff1dd214
[NBF]root.Data
5aff1dd215
[NBF]root.Data
5aff1dd216
[NBF]root.Data
5aff1dd217
[NBF]root.Data
5aff1dd218
[NBF]root.Data
5aff1dd219
[NBF]root.Data
5aff1dd22
[NBF]root.Data
5aff1dd220
[NBF]root.Data
5aff1dd221
[NBF]root.Data
5aff1dd222
[NBF]root.Data
5aff1dd223
[NBF]root.Data
5aff1dd224
[NBF]root.Data
5aff1dd225
[NBF]root.Data
5aff1dd226
[NBF]root.Data
5aff1dd227
[NBF]root.Data
5aff1dd228
[NBF]root.Data
5aff1dd229
[NBF]root.Data
5aff1dd23
[NBF]root.Data
5aff1dd230
[NBF]root.Data
5aff1dd231
[NBF]root.Data
5aff1dd232
[NBF]root.Data
5aff1dd233
[NBF]root.Data
5aff1dd234
[NBF]root.Data
5aff1dd235
[NBF]root.Data
5aff1dd236
[NBF]root.Data
5aff1dd237
[NBF]root.Data
5aff1dd238
[NBF]root.Data
5aff1dd239
[NBF]root.Data
5aff1dd24
[NBF]root.Data
5aff1dd240
[NBF]root.Data
5aff1dd241
[NBF]root.Data
5aff1dd242
[NBF]root.Data
5aff1dd243
[NBF]root.Data
5aff1dd244
[NBF]root.Data
5aff1dd245
[NBF]root.Data
5aff1dd246
[NBF]root.Data
5aff1dd247
[NBF]root.Data
5aff1dd248
[NBF]root.Data
5aff1dd249
[NBF]root.Data
5aff1dd25
[NBF]root.Data
5aff1dd250
[NBF]root.Data
5aff1dd251
[NBF]root.Data
5aff1dd252
[NBF]root.Data
5aff1dd253
[NBF]root.Data
5aff1dd254
[NBF]root.Data
5aff1dd255
[NBF]root.Data
5aff1dd256
[NBF]root.Data
5aff1dd257
[NBF]root.Data
5aff1dd258
[NBF]root.Data
5aff1dd259
[NBF]root.Data
5aff1dd26
[NBF]root.Data
5aff1dd260
[NBF]root.Data
5aff1dd261
[NBF]root.Data
5aff1dd262
[NBF]root.Data
5aff1dd27
[NBF]root.Data
5aff1dd28
[NBF]root.Data
5aff1dd29
[NBF]root.Data
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0032
ID:0
ID:0033
ID:0
ID:0034
ID:0
ID:0035
ID:0
ID:0036
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Reflective Loader
Malicious
Overlay_7940c33a.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
CollectorTracer.AttributeTask
DistributorTask.VisitorTask
SimpleTask.TaskFormatter
TaskConfiguration.AuthenticatorTask
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path pe:exe>pe:dll~T1059.007>pe:rsrc>bin
Shape pe:exe>pe:dll>pe:rsrc>bin
malicious 4 nodes
Path pe:exe>pe:dll~T1059.007>bin
Shape pe:exe>pe:dll>bin
malicious 3 nodes
Name Value
Module Name
eg9Qx1HsMna8nT
Full Name
eg9Qx1HsMna8nT
EntryPoint
System.Void yYg1b2WtDjn83.4Pjigb6FDsy2::bo4F7oGq()
Scope Name
eg9Qx1HsMna8nT
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
eg9Qx1HsMna8nT
Assembly Version
26.8.10.173
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void yYg1b2WtDjn83.4Pjigb6FDsy2::bo4F7oGq()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void cr9MBpy2o3dH5x.8KgjBg1rb6iA::.ctor()
stloc.1 <null>
ret <null>
ldtoken System.Void yYg1b2WtDjn83.4Pjigb6FDsy2::bo4F7oGq()
pop <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
eg9Qx1HsMna8nT
Full Name
eg9Qx1HsMna8nT
EntryPoint
System.Void yYg1b2WtDjn83.4Pjigb6FDsy2::bo4F7oGq()
Scope Name
eg9Qx1HsMna8nT
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
eg9Qx1HsMna8nT
Assembly Version
26.8.10.173
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
0
Main Method
System.Void yYg1b2WtDjn83.4Pjigb6FDsy2::bo4F7oGq()
Main IL Instruction Count
7
Main IL
nop <null>
newobj System.Void cr9MBpy2o3dH5x.8KgjBg1rb6iA::.ctor()
stloc.1 <null>
ret <null>
ldtoken System.Void yYg1b2WtDjn83.4Pjigb6FDsy2::bo4F7oGq()
pop <null>
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙