Malicious
531962f97a5f6ae7580f8d895d9177f9
PE Executable
MD5: 531962f97a5f6ae7580f8d895d9177f9
Size: 1.68 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 531962f97a5f6ae7580f8d895d9177f9 |
| Sha1 | ddd0d82daf6548bf6b6d92aafbeded924ec8ee4d |
| Sha256 | a8efe4ee25da7ed2f6255f18f3db86e0a204c7b4a275e57bcfc9a6adf3c52532 |
| Sha384 | ac5065afb3563605439cdb84a4c24e51286ff1aeabc5811ab89157b1128f1f4b1828bfa4ee557823544365fe08b68404 |
| Sha512 | c7b4a645c3c1bfd0b7c02b78ca6af3e87bceab6c06a26cbc1724236c472ee21c4e7df0ea2f08359a460f56475877a8270a7114eb5f2625470f2fc41a0a40bda1 |
| SSDeep | 49152:gxSwcvnjqj1WjFnftb6OSn/5Ydgn4CLHfWDZkrrb:gxTcvnjqjcZh63ENtkr |
| TLSH | 2D751258164FC816C8934F7549A0E3B416B48F58A522C30BAEFE7EAB792F75A2C447C1 |
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
4 / 4
Path
pe:exe>pe:rsrc>img
Shape
pe:exe>pe:rsrc>img
malicious
3 nodes
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: UEqw.pdb |
| Module Name | UEqw.exe |
| Full Name | UEqw.exe |
| EntryPoint | System.Void Tq.i2::j4() |
| Scope Name | UEqw.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | UEqw |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 116 |
| Main Method | System.Void Tq.i2::j4() |
| Main IL Instruction Count | 12 |
| Main IL | |
| Module Name | UEqw.exe |
| Full Name | UEqw.exe |
| EntryPoint | System.Void Tq.i2::j4() |
| Scope Name | UEqw.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | UEqw |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 116 |
| Main Method | System.Void Tq.i2::j4() |
| Main IL Instruction Count | 12 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.