Malicious
Malicious

088d432df4ccadb352081564a4f4518b

PE Executable
MD5: 088d432df4ccadb352081564a4f4518b
Size: 1.15 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 088d432df4ccadb352081564a4f4518b
Sha1 a5dd33113852f6d14e0da0a40eec1b1275569d45
Sha256 053b117e9ed3d97ed109590d414e1db9321475564e8ecd120221a56610b05c0c
Sha384 c259b932584f6476dc3e8177deb572aedb4c06a0ec6145c4bbd19d51e6976d83859648a7a730adf67ae71154c83277ca
Sha512 0e72d767f8d4534f72450a9c237298b8d170b7180473a67674e64f53f181865f5158a35bfd9a5f869d076cdd7ab7bd6e262f159ea3ebe683609278f06c7389b2
SSDeep 24576:Qp50y90wK86lUZixEd/fDmOExIW613NyzG9xwpU:Qpd0TIixo/625yacU
TLSH 1335F054160BD802D4D587B6F8F0D2B422A44ECEFAE3C3936FE93FB779267825594242
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
JIZ.dIb.resources
$this.Icon
[NBF]root.IconData
HI
[NBF]root.Data
Ey1.JyR.resources
mwSe.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RetroRaycaster.Properties.Resources.resources
TiYD
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
mwSe.exe
Full Name
mwSe.exe
EntryPoint
System.Void p4.LW::Vd()
Scope Name
mwSe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mwSe
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
125
Main Method
System.Void p4.LW::Vd()
Main IL Instruction Count
11
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0024: ldc.i4.0
ret <null>
newobj System.Void JIZ.dIb::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000A: ret
call System.Void E7H.F7x::aXX()
br IL_000B: newobj System.Void JIZ.dIb::.ctor()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_001A: call System.Void E7H.F7x::aXX()
Module Name
mwSe.exe
Full Name
mwSe.exe
EntryPoint
System.Void p4.LW::Vd()
Scope Name
mwSe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mwSe
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
125
Main Method
System.Void p4.LW::Vd()
Main IL Instruction Count
11
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0024: ldc.i4.0
ret <null>
newobj System.Void JIZ.dIb::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000A: ret
call System.Void E7H.F7x::aXX()
br IL_000B: newobj System.Void JIZ.dIb::.ctor()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_001A: call System.Void E7H.F7x::aXX()
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
JIZ.dIb.resources
$this.Icon
[NBF]root.IconData
HI
[NBF]root.Data
Ey1.JyR.resources
mwSe.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
RetroRaycaster.Properties.Resources.resources
TiYD
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙