Malicious
PE Executable
MD5: 565250285d77211d7a92878d1f3fa5f1
Size: 1.07 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
High
| MD5 | 565250285d77211d7a92878d1f3fa5f1 |
| Sha1 | 2b82a41eb2162bf0673eda98ea5e97b75213e0db |
| Sha256 | faf4efd14cfe28db1bc8fe68f9b8920207663ae936409aa2576eda80c1cb87cc |
| Sha384 | 3be1512c07efe99d9398b5b988871d8aa27bc2e70bb41ea9c0aca4bcf0ba019d3f7b17acce57fad9ee68ceb188502563 |
| Sha512 | 1bbf7fa9f6580c7b4adbef8554c2a57d52b7fbeba0caf070a089aaa8e0addaf9b45a7aab0d6489fa3b6de2ba0e63d7c3037b3836bee631b6a62934654e0450ef |
| SSDeep | 24576:ZjP/2oSdvHWBc9jJqfMtsyNrDxuLehlZk:Zb/2oSJWAqEsyFDxIj |
| TLSH | 3B3502582127DC12D1D61FB048A1E3B517A44F80E923C303DEFA7DEBB97B79A6E44291 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
4 / 4
Path
pe:exe>pe:rsrc>img
Shape
pe:exe>pe:rsrc>img
malicious
3 nodes
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
| Name | Value |
|---|---|
| Module Name | ffUJ.exe |
| Full Name | ffUJ.exe |
| EntryPoint | System.Void jw.K3::U2() |
| Scope Name | ffUJ.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | ffUJ |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 149 |
| Main Method | System.Void jw.K3::U2() |
| Main IL Instruction Count | 16 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: ffUJ.pdb |
| Module Name | ffUJ.exe |
| Full Name | ffUJ.exe |
| EntryPoint | System.Void jw.K3::U2() |
| Scope Name | ffUJ.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | ffUJ |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 149 |
| Main Method | System.Void jw.K3::U2() |
| Main IL Instruction Count | 16 |
| Main IL | |