Malicious
Malicious

531962f97a5f6ae7580f8d895d9177f9

PE Executable
MD5: 531962f97a5f6ae7580f8d895d9177f9
Size: 1.68 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 531962f97a5f6ae7580f8d895d9177f9
Sha1 ddd0d82daf6548bf6b6d92aafbeded924ec8ee4d
Sha256 a8efe4ee25da7ed2f6255f18f3db86e0a204c7b4a275e57bcfc9a6adf3c52532
Sha384 ac5065afb3563605439cdb84a4c24e51286ff1aeabc5811ab89157b1128f1f4b1828bfa4ee557823544365fe08b68404
Sha512 c7b4a645c3c1bfd0b7c02b78ca6af3e87bceab6c06a26cbc1724236c472ee21c4e7df0ea2f08359a460f56475877a8270a7114eb5f2625470f2fc41a0a40bda1
SSDeep 49152:gxSwcvnjqj1WjFnftb6OSn/5Ydgn4CLHfWDZkrrb:gxTcvnjqjcZh63ENtkr
TLSH 2D751258164FC816C8934F7549A0E3B416B48F58A522C30BAEFE7EAB792F75A2C447C1
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
UEqw.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SoftwareRenderer.Properties.Resources.resources
TK
[NBF]root.Data
EkBb
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: UEqw.pdb
Module Name
UEqw.exe
Full Name
UEqw.exe
EntryPoint
System.Void Tq.i2::j4()
Scope Name
UEqw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
UEqw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
116
Main Method
System.Void Tq.i2::j4()
Main IL Instruction Count
12
Main IL
br IL_001B: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0010: call System.Void Nco.gcD::KUN()
call System.Void Nco.gcD::KUN()
br IL_0025: newobj System.Void jWs.pWm::.ctor()
ret <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: ldc.i4.0
newobj System.Void jWs.pWm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001A: ret
Module Name
UEqw.exe
Full Name
UEqw.exe
EntryPoint
System.Void Tq.i2::j4()
Scope Name
UEqw.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
UEqw
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
116
Main Method
System.Void Tq.i2::j4()
Main IL Instruction Count
12
Main IL
br IL_001B: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0010: call System.Void Nco.gcD::KUN()
call System.Void Nco.gcD::KUN()
br IL_0025: newobj System.Void jWs.pWm::.ctor()
ret <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: ldc.i4.0
newobj System.Void jWs.pWm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001A: ret
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
UEqw.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
SoftwareRenderer.Properties.Resources.resources
TK
[NBF]root.Data
EkBb
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙