Malicious
PE Executable
MD5: 52516a951d018b0131be36f4835a1d27
Size: 2 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 52516a951d018b0131be36f4835a1d27 |
| Sha1 | f5ca9a4c80567d1c2ff6ba493a62d88e1ee3a5f1 |
| Sha256 | 2780990915f461b0e76cb57a125a730646cda5e37071cb9a5addc820b1febac2 |
| Sha384 | f2fdc7ab721fa9fbad948c13f21bfd1ba48e81941cd9b80831a593378f2524ba9de2e91cf589d1a8a2c0fe5d450a92c3 |
| Sha512 | b79f8dd7eb8bc8201d50069cb4fea05a11903777894fb9d806eb213ef5a32cfdee2dd431235bf8188be462dd704d7afab3246f91fe4c68dbfb3c5be79574b836 |
| SSDeep | 24576:32yWGWRCcV/Cov8XgVEW0fIdGh/UDt343AjMKzf/s3TVO1FCY8zlauRJWJ9yu:GTfV/C+8Xg/0fm6sRIesTVO10rR1u |
| TLSH | D495D03036B6D149E5BA0B710CB556C027B63B667E44CB4D6898224DDD33B27CB12EEB |
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
4 / 4
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
Path
pe:exe>pe:rsrc>img
Shape
pe:exe>pe:rsrc>img
malicious
3 nodes
| Name | Value |
|---|---|
| Module Name | kVps.exe |
| Full Name | kVps.exe |
| EntryPoint | System.Void F7J.r7o::F7S() |
| Scope Name | kVps.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | kVps |
| Assembly Version | 8.3.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 673 |
| Main Method | System.Void F7J.r7o::F7S() |
| Main IL Instruction Count | 12 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: kVps.pdb |