Malicious
Malicious

77c778b81e608b32164f2430e47205f1

PE Executable
MD5: 77c778b81e608b32164f2430e47205f1
Size: 1.23 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 77c778b81e608b32164f2430e47205f1
Sha1 2dd344927b57b49a1051b046fa6c34bb58b253d6
Sha256 ae0a4363fd2c67c3ed725d3fbfe28c2aae97639034920619da14cdb154239cb7
Sha384 1c492ae0dee3e8ec8fd05744bb4985be4a3059a84649e03a737b4f43ecf075b8dc89fcc4bf6d5e1530b15e5419958ca4
Sha512 c06dc34927c8a6bf6e560e1ca62db50da6c8d67e6b5038b86689beffe659f373302afbec632f9efc765886c925cbf2d28bfdc0e8ed869bfd46a57db7927c361f
SSDeep 24576:HYGjP/2oSdvGxc9Z8uNm+HOTu89LgBDJnN36cXRNtaxwoikpDvFjFuEHk97:5b/2oSX9ZvNm3Tb2nNKcXRnMw9kVFjEl
TLSH 2245EF142216DD12C5D61AB0D8E1E2FF42B05E47E912F2075AEA7E9F7876746FB802C3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
HD.Wi.resources
nlW.llN.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
HydroReservoir.Properties.Resources.resources
Pro
[NBF]root.Data
VTFb
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Module Name
LVHN.exe
Full Name
LVHN.exe
EntryPoint
System.Void Rp.WR::mL()
Scope Name
LVHN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LVHN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void Rp.WR::mL()
Main IL Instruction Count
16
Main IL
br IL_000F: nop
call System.Void qwJ.Tw7::aA9()
br IL_001A: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002A: nop
nop <null>
newobj System.Void HD.Wi::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0036: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void qwJ.Tw7::aA9()
nop <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
LVHN.exe
Full Name
LVHN.exe
EntryPoint
System.Void Rp.WR::mL()
Scope Name
LVHN.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
LVHN
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void Rp.WR::mL()
Main IL Instruction Count
16
Main IL
br IL_000F: nop
call System.Void qwJ.Tw7::aA9()
br IL_001A: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002A: nop
nop <null>
newobj System.Void HD.Wi::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0036: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void qwJ.Tw7::aA9()
nop <null>
ret <null>
.Net Resources
HD.Wi.resources
nlW.llN.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
HydroReservoir.Properties.Resources.resources
Pro
[NBF]root.Data
VTFb
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙