Malicious
Malicious

0ff636fd478af4b4ef4c00cb000caee7

PE Executable
MD5: 0ff636fd478af4b4ef4c00cb000caee7
Size: 103.42 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0ff636fd478af4b4ef4c00cb000caee7
Sha1 222e82e4ca5e7a57bb7733767ca42fd999f8e950
Sha256 88ed1c6d2164f08137cf47668c9ffb55c868d4cfb172bb04198ca954f0bda4b9
Sha384 fae36b5a6b60b0a2f0231b5b6e43feb1ede3506930ee3df875d9368931ae4cdddb8ddf7646f95e436efcc930cfc33eff
Sha512 667b4cbc080d6b02260870a5a5a4f866f511da3adb716aaf0190bec28f9382b4e721186dfa128816e1c43ea65bb72841eed2ee6f2370119cdfc2c607b2087cc3
SSDeep 1536:tm97CZ/1pXrd5N1AxWEBDkvdMqCDv+Lo5N5MKZ:U97c7XTNsWEBDkvyPb+Lo9Z
TLSH 35A34B82B28084F6C5A68639C9D24B859371BC25473923CF37A077691F777D86E7E3A0
PeID
Armadillo v4.xMicrosoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
Resources
MSI
ID:0000
Root Entry
䡀䌏䈯
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䓞䕪䇤䠨
䡀䕙䓲䕨䜷
䡀䈛䒰䈹䌏䈯
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀䕌䄨䈷䒏䇯䕨
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䄕䑸䋦䒌䇱䗬䒬䠱
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
RT_GROUP_CURSOR4
ID:0080
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 4 STICH kept: 1secondary ignored: 3
bin 3

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>scr:ps1~T1027~T1059.001
Shape pe:exe>scr:ps1
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: e:\Develope\msi2exe\x64\release\msi2exestub.pdb
Deobfuscated PowerShell UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
-argumhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
Resources
MSI
ID:0000
Root Entry
䡀䌏䈯
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䓞䕪䇤䠨
䡀䕙䓲䕨䜷
䡀䈛䒰䈹䌏䈯
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀䕌䄨䈷䒏䇯䕨
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䄕䑸䋦䒌䇱䗬䒬䠱
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
RT_GROUP_CURSOR4
ID:0080
ID:1033
RT_MANIFEST
ID:0001
ID:1033
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[Deobfuscated PS]
Malicious
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
Start-huhuhuhuhuhuhuhuhuhuhu
0ff636fd478af4b4ef4c00cb000caee7 › CmdFile › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
-argumhuhuhuhuhuhuhuhuhuhuhu
0ff636fd478af4b4ef4c00cb000caee7 › CmdFile › [PowerShell Command] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙