Malicious
Malicious

347d1503edc764f752d63edfbbe5bab0

PE Executable
MD5: 347d1503edc764f752d63edfbbe5bab0
Size: 39.42 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 347d1503edc764f752d63edfbbe5bab0
Sha1 ef0da2c50aa02fcec968124a42877f06691ae1e1
Sha256 496d17723897d32e41d985f65ee3b97058a09018fa8d29a75f91e4ec1104a10c
Sha384 5a818465f19b36ce0f4aa8ba06d840485fb8293699fd228e329ee7fdb35aae4412f9d0c9947e731a56501bcebd84b268
Sha512 de337f2814c6ad2dfe43b6cf421333e59d09399fa794d3212137ddd80bb3260181538e5c7987ef249af0b065e9dac98e39b8325207d2cf314f841790bcf98dc5
SSDeep 768:NO+idK+XquYRnzwIKKZ7msohaKECJHWaP88sqFB1hSu2fUR:Es+6fRAaKr2Mz+iR
TLSH 27034B73AB6F8860C5B91A3BCC56816403F1E3015923DF2E748D930DBE93397D78A666
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
curso.Resources.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll>pe:rsrc>bin
Shape pe:dll>pe:rsrc>bin
malicious 3 nodes
Path pe:dll>bin
Shape pe:dll>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: curso.pdb
Module Name
curso.dll
Full Name
curso.dll
Scope Name
curso.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
curso
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
23
Main Method
Not found or no body
Module Name
curso.dll
Full Name
curso.dll
Scope Name
curso.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
curso
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.7.2
Total Strings
23
Main Method
Not found or no body
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
curso.Resources.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙