Malicious
Malicious

799c821aef52ab674d622b70b337fea9

PE Executable
MD5: 799c821aef52ab674d622b70b337fea9
Size: 1.05 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 799c821aef52ab674d622b70b337fea9
Sha1 678ab596d3099155741d145b57f050f62347a67e
Sha256 fe480b90b31bd8709b94e921b6523bd7759a34ff2b13cde965125af19d07fb22
Sha384 cb81bc75e93658a5c4c4ea9c2f2c76917dfdff58204e04c376f7c106541fc6e4b7df1b2d29a9300fb92f2759d674a138
Sha512 4156dec8c65766925145d06885925e1f0d3d27b83e4a06579204c8ac1e947fd638191a1fa974a3e788343819dcad327f27d2ec7cb460e99598945c168f77024e
SSDeep 24576:aAnqXULsmDodaYZMOkmZ11p36tYcecFQnHujt2QXqdItSE7OAlfw:G43KMOfZ1LqtYcXQFgqGtHOAlI
TLSH 5025E0186557CA62CC5433B3CA62CAF422735D9BD2D3C3EB56F97DA77A30BB41448282
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
hJO.mJI.resources
$this.Icon
[NBF]root.IconData
TdVU.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
InkWell.Properties.Resources.resources
UDP
[NBF]root.Data
IEUe
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
TdVU.exe
Full Name
TdVU.exe
EntryPoint
System.Void TZ.LA::S9()
Scope Name
TdVU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TdVU
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
378
Main Method
System.Void TZ.LA::S9()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
ret <null>
call System.Void YP0.gPK::ilv()
br IL_001D: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0007: call System.Void YP0.gPK::ilv()
nop <null>
newobj System.Void xm.ik::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0005: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0011: nop
Module Name
TdVU.exe
Full Name
TdVU.exe
EntryPoint
System.Void TZ.LA::S9()
Scope Name
TdVU.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
TdVU
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
378
Main Method
System.Void TZ.LA::S9()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
ret <null>
call System.Void YP0.gPK::ilv()
br IL_001D: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0007: call System.Void YP0.gPK::ilv()
nop <null>
newobj System.Void xm.ik::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0005: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0011: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
hJO.mJI.resources
$this.Icon
[NBF]root.IconData
TdVU.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
InkWell.Properties.Resources.resources
UDP
[NBF]root.Data
IEUe
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙