Malicious
PE Executable
MD5: 4de31170ddc61263da6cf06850ef4cc9
Size: 148.99 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 4de31170ddc61263da6cf06850ef4cc9 |
| Sha1 | bb9dd6b3392b6f850525a05f51cf9a817c01918c |
| Sha256 | 652b4e9e70a97e6c4039975b91c79e4e763457c2cfe8b920204b6cf71ecf808f |
| Sha384 | d0713c0855aed977b0246d2b091c5fd91cd787571a8807fa84f466cf85583219218937a38d9912c1eb5d8d856b019be6 |
| Sha512 | cd2e7921a696877e6997e2bcf831fa2a1478745c1c6934421d4eb3efa63e3068936127ea66457ce71aa66b0b7c4cf2d6d1b9ff74d28c36ced29147c22c7afa06 |
| SSDeep | 1536:hZ+dp7oepetWX83HcKvl3SGMJ8xZqAQ/Wuags5m4aOF22rUQ8dBYlPNAeG5/tq:hZ9KmDcRJ8xZqA+Wu8m4aOkoPNa5/tq |
| TLSH | F0E34A16A5688624DAF3127A6DE76100DF33002F4324AA44FACD91CE7FB255E8537FB6 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Malicious
Malicious
Malicious
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 4
STICH kept: 2secondary ignored: 2
bin
2Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:exe>scr:ps1~T1027~T1059.001
Shape
pe:exe>pe:exe>scr:ps1
malicious
3 nodes
Path
pe:exe>pe:exe>scr:ps1~T1059.001
Shape
pe:exe>pe:exe>scr:ps1
technique3 nodes
| Name | Value |
|---|---|
| Module Name | Pulse-Tweaks-Setup.exe |
| Full Name | Pulse-Tweaks-Setup.exe |
| EntryPoint | System.Int32 Setup::Main(System.String[]) |
| Scope Name | Pulse-Tweaks-Setup.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Pulse-Tweaks-Setup |
| Assembly Version | 1.2.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 87 |
| Main Method | System.Int32 Setup::Main(System.String[]) |
| Main IL Instruction Count | 119 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | Pulse-Tweaks-Setup.exe |
| Full Name | Pulse-Tweaks-Setup.exe |
| EntryPoint | System.Int32 Setup::Main(System.String[]) |
| Scope Name | Pulse-Tweaks-Setup.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Pulse-Tweaks-Setup |
| Assembly Version | 1.2.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 87 |
| Main Method | System.Int32 Setup::Main(System.String[]) |
| Main IL Instruction Count | 119 |
| Main IL | |
Deobfuscated PowerShell
UNKNWOWNmalicious
@echo
huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell
UNKNWOWNmalicious
Prohuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential