Malicious
Malicious

7cae9aa7a3ae51211c08017e8f7756a6

PE Executable
MD5: 7cae9aa7a3ae51211c08017e8f7756a6
Size: 1.1 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 7cae9aa7a3ae51211c08017e8f7756a6
Sha1 cbf062d3e8d36d9a3e13aec4b3f7ce0da03f8832
Sha256 555dd2874eafc9cfa3015ba447a866bc7262b7bf40803ea5bd8b8d7e6596fbe9
Sha384 3bfe0c723279c38591c7dd6004b65bdce79546ebad2e8f641a6a6199f85f88a77a7d13d2e77c19b99e1946b660bed1f3
Sha512 5ce397c2cb5f800fc7261aa74724a4855544e9d58f3774d1d5f185e364e82e89b7b96ce16313c9e82f63331277cb577469904d4cf04774f657b6381e5f7407a9
SSDeep 24576:PJFosmVaQw0tJEhjCtbNAhpwOl345g4iq:x+3hwBCtbqGGYtiq
TLSH 1A35E1086157CB62DC5437B3CEB2CAF422735D9AD583C2EB56F87DA73A31BB41488642
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
fFs.CFF.resources
$this.Icon
[NBF]root.IconData
lyWQ.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
InkWell.Properties.Resources.resources
UDP
[NBF]root.Data
kiDu
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Module Name
lyWQ.exe
Full Name
lyWQ.exe
EntryPoint
System.Void Hr.nL::ST()
Scope Name
lyWQ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lyWQ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
378
Main Method
System.Void Hr.nL::ST()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0011: call System.Void FEc.bE7::pRo()
call System.Void FEc.bE7::pRo()
br IL_001B: nop
nop <null>
newobj System.Void g9.kw::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002B: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
lyWQ.exe
Full Name
lyWQ.exe
EntryPoint
System.Void Hr.nL::ST()
Scope Name
lyWQ.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
lyWQ
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
378
Main Method
System.Void Hr.nL::ST()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0011: call System.Void FEc.bE7::pRo()
call System.Void FEc.bE7::pRo()
br IL_001B: nop
nop <null>
newobj System.Void g9.kw::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002B: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: nop
.Net Resources
fFs.CFF.resources
$this.Icon
[NBF]root.IconData
lyWQ.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
InkWell.Properties.Resources.resources
UDP
[NBF]root.Data
kiDu
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙