Malicious
Malicious

3ff1129f6b1a2480b60cf4002adb2506

Share on LinkedIn
Print
PE Executable
MD5: 3ff1129f6b1a2480b60cf4002adb2506
Size: 1.2 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 3ff1129f6b1a2480b60cf4002adb2506
Sha1 45822cd242fb4a53e2759715bd5089a81d162c02
Sha256 db08fc16b43a9d245aa7f1ba04123fd9cc321430601d44fb5b479f04cee8ec45
Sha384 7f0b440b9d5d76ebe2f9e0d25b0a5d857c38140130a40695d40187e9343dc01d8481882abe1090c7283913161f02d933
Sha512 974fab184343b91e5b65bf69c11bc2847c1a05ef484ee5c10766b63ab5800ac51017e457dc12e763fc55b4909eb556614f369b9fd6e8fdf8f1f1bcb144be1b2e
SSDeep 24576:TTD1ojP/2oSdvOLRfA43XbnmTgcrmfoS3HsLQ:3yb/2oSMLR42rnGg
TLSH 2345E0142116DC12E0E25AB1D8E0E2FF06745E87E522F6079AEA7D9F7536784FB842C3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
.Net Resources
y9.ae.resources
HAS.UAJ.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
HydroReservoir.Properties.Resources.resources
Pro
[NBF]root.Data
wazm
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Module Name
dwFF.exe
Full Name
dwFF.exe
EntryPoint
System.Void tv.Rx::uc()
Scope Name
dwFF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dwFF
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void tv.Rx::uc()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
newobj System.Void y9.ae::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0021: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0023: call System.Void VGG.NGA::SOt()
nop <null>
ret <null>
call System.Void VGG.NGA::SOt()
br IL_0005: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0015: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
dwFF.exe
Full Name
dwFF.exe
EntryPoint
System.Void tv.Rx::uc()
Scope Name
dwFF.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
dwFF
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void tv.Rx::uc()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
newobj System.Void y9.ae::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0021: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0023: call System.Void VGG.NGA::SOt()
nop <null>
ret <null>
call System.Void VGG.NGA::SOt()
br IL_0005: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0015: nop
An error has occurred. This application may no longer respond until reloaded. Reload 🗙