Malicious
PE Executable
MD5: 2872b4c1c4e400dbf4c98b7d691848cf
Size: 1.07 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very high
| MD5 | 2872b4c1c4e400dbf4c98b7d691848cf |
| Sha1 | 351af0f6443e06bbab8174222c593dfb18a84586 |
| Sha256 | 1e431d109f675c8c9a4cadd1c6cb40c3205db4d6634a437bcf6c8826fd57a746 |
| Sha384 | 0e1602954cceeb92f0d0afdab2493b66d69a8a28a7b0f697fce1bb930a7f750d7c3c455d94ac71f9a9e61b17a5c87633 |
| Sha512 | 3fd4258af14c98ec1a83d30d0bcebfd6d36ec7721b53c0532025f36269e0b669bc73ab1b5e30e981eb52ab7d3426c99480af72ae404acd24bc1a6c7c3e4c3f1f |
| SSDeep | 12288:DZOfrHoMkq1RX9R3irp4oQUWFv5rfb62oJv8GHpiIjBMXAAKgtZxvkjt62p30K0O:8xxfX9E3MhrfGcGHN8KMZxUpvnB |
| TLSH | 4A35CF1636624E91C2850F33C1DB950087E2A983F9E7F74FB68413661D173EEE947AA3 |
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
Path
pe:exe>bin
Shape
pe:exe>bin
malicious
2 nodes
| Name | Value |
|---|---|
| Module Name | Jtwzola.exe |
| Full Name | Jtwzola.exe |
| EntryPoint | System.Void FYho8oYh0TOJTx4s6u.QH6IqUg2QxfQsNG4jA::KPYn8cvb6() |
| Scope Name | Jtwzola.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Jtwzola |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.0 |
| Info | PE Detect: PeReader OK (file layout) |
| Total Strings | 41 |
| Main Method | System.Void FYho8oYh0TOJTx4s6u.QH6IqUg2QxfQsNG4jA::KPYn8cvb6() |
| Main IL Instruction Count | 96 |
| Main IL | |