Malicious
Malicious

37d5276210a361c53ad7a6c5252b3f1c

PE Executable
MD5: 37d5276210a361c53ad7a6c5252b3f1c
Size: 1.1 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 37d5276210a361c53ad7a6c5252b3f1c
Sha1 a7979f8e6ab604dde001af319bbf18464e34fce3
Sha256 e5530ac3388f55153f5ae4ebf01abdfbcb1a2e76ffac7e8ca1ebbcac3364fb3a
Sha384 84c14eb38f02541ee855b62930fc91be5294bcc14569a7860f1e1dd66fcfa1d79337fa50390711379d1f0530b7879179
Sha512 d7a0b56d75a59d613b1eafc65bac0d633ec3525a3dd2ecb07b09c4ed478297eb5e6d176a6b75bfb506076a60b11ce43c5177c5d623d781f783b2a17e35d0ddb9
SSDeep 24576:QYiiTi1hhjpVa/Ke0MtEDLUup9JsRHNb0V7DsWXZhsvGdUz:QYmhrYK5M+DdjJsvinlZCgU
TLSH F835E095A316C803D6851BB4C8A0F7B51374AEFCED07C353BAFA7DDB79293462885212
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
lb.nf.resources
Qrp.vrX.resources
$this.Icon
[NBF]root.IconData
UrS.pro.resources
$this.Icon
[NBF]root.IconData
contextMenu.TrayLocation
Bi
[NBF]root.Data
notifyIcon.Icon
[NBF]root.IconData
timer.TrayLocation
notifyIcon.TrayLocation
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Clock.Properties.Resources.resources
rXGN
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
TTjv.exe
Full Name
TTjv.exe
EntryPoint
System.Void P1W.B1j::X1g()
Scope Name
TTjv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TTjv
Assembly Version
10.0.26100.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
182
Main Method
System.Void P1W.B1j::X1g()
Main IL Instruction Count
16
Main IL
br IL_001F: nop
nop <null>
newobj System.Void UrS.pro::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002A: nop
call System.Void awf.qw7::VQ5()
br IL_0005: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002C: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0015: call System.Void awf.qw7::VQ5()
Module Name
TTjv.exe
Full Name
TTjv.exe
EntryPoint
System.Void P1W.B1j::X1g()
Scope Name
TTjv.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TTjv
Assembly Version
10.0.26100.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
182
Main Method
System.Void P1W.B1j::X1g()
Main IL Instruction Count
16
Main IL
br IL_001F: nop
nop <null>
newobj System.Void UrS.pro::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002A: nop
call System.Void awf.qw7::VQ5()
br IL_0005: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002C: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0015: call System.Void awf.qw7::VQ5()
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
lb.nf.resources
Qrp.vrX.resources
$this.Icon
[NBF]root.IconData
UrS.pro.resources
$this.Icon
[NBF]root.IconData
contextMenu.TrayLocation
Bi
[NBF]root.Data
notifyIcon.Icon
[NBF]root.IconData
timer.TrayLocation
notifyIcon.TrayLocation
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Clock.Properties.Resources.resources
rXGN
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙