Suspect
PE Executable
MD5: 396a9a33360a6597562033f7c6a09dfb
Size: 13.33 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Very low
| MD5 | 396a9a33360a6597562033f7c6a09dfb |
| Sha1 | f15388fb52e60b669b4feb5beee3a68dbe445e49 |
| Sha256 | 6b1ededee55d8822840dd3d2b264d0176a0400906c511188c291c64e1fe9ad77 |
| Sha384 | 559ac3ec0b07297e746160134d9d45a086dcbc776c3e69b760cb1b25caa505b314cc92ae86fad0b85df8f6885466bf32 |
| Sha512 | 0a0057da838775b7cb55f0b483d9d7acd893e5ce037289dc44d580cb8981ce07fd62e82182019d84f2400b7db8a54bf19da079711e6bfc101b4fb943f756e263 |
| SSDeep | 196608:MdrUvHqHxcp9ym3nltDUJViHxcp9ym31Hxcp9ym3WHxcp9ym37Hxcp9ym3eHxcpp:Mdru4GplpBGpnGpkGpFGpsGp |
| TLSH | 4ED623116BF89678E0B62A35E876A0B1A1377D119D23D26E23247D1E3C71E80C9B3777 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 12
STICH kept: 1secondary ignored: 11
bin
10img
1Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:dll>pe:dll
Shape
pe:exe>pe:dll>pe:dll
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | FinalTry.exe |
| Full Name | FinalTry.exe |
| EntryPoint | System.Void Program::Main() |
| Scope Name | FinalTry.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | FinalTry |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 27 |
| Main Method | System.Void Program::Main() |
| Main IL Instruction Count | 124 |
| Main IL | |
| Module Name | FinalTry.exe |
| Full Name | FinalTry.exe |
| EntryPoint | System.Void Program::Main() |
| Scope Name | FinalTry.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | FinalTry |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 27 |
| Main Method | System.Void Program::Main() |
| Main IL Instruction Count | 124 |
| Main IL | |