Malicious
Malicious

83f7f0a5a5475b33c66e39c8afe6c293

PE Executable
MD5: 83f7f0a5a5475b33c66e39c8afe6c293
Size: 1.45 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 83f7f0a5a5475b33c66e39c8afe6c293
Sha1 294c1639e844494e96fe1e984d1a8e8f15d6a503
Sha256 d3ac1fa2c9bb8ef73f91f699b9896f45a65021c5b1e4bbff1b1ea0b701066f81
Sha384 ae3ad989c5272da9a1d7071c0dcfbd4ed4817b9172136a4dbead8854be400e0118fd4273823c846ba8695fae9df9d12f
Sha512 94d68390da2c3a20e32ec77fe5bf9b0c8fd168431d6785ae27699e6884598d3c785344692eb7793d9645dce1d93989c99bd31870db532a72647522267380684e
SSDeep 24576:Q+hbtQ3pjsLz4i5vQvPesio3uy3zCtA06mFgpw3uthpLQDegdI:NQ35Kz35vQ+Po+dtA06mFT3uRDg2
TLSH F565CE04221BDA23C25526B5C9B3E1F41374DE84D933C32B49E6BDB77F36EB5A5402A2
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Dh.js.resources
$this.Icon
[NBF]root.IconData
knNS.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
FlaxRetting.Properties.Resources.resources
icons8_graph_report_50
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_purchase_order_50
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_customer_26
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_package_64
[NBF]root.Data
[NBF]root.Data-preview.png
sDzN
[NBF]root.Data
[NBF]root.Data-preview.png
Btlj
[NBF]root.Data
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
knNS.exe
Full Name
knNS.exe
EntryPoint
System.Void qS.jb::qi()
Scope Name
knNS.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
knNS
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
257
Main Method
System.Void qS.jb::qi()
Main IL Instruction Count
16
Main IL
br IL_002D: nop
call System.Void e40.y4Z::tmV()
br IL_0011: nop
nop <null>
ret <null>
nop <null>
newobj System.Void Dc.td::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000F: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void e40.y4Z::tmV()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0021: nop
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Dh.js.resources
$this.Icon
[NBF]root.IconData
knNS.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
FlaxRetting.Properties.Resources.resources
icons8_graph_report_50
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_purchase_order_50
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_customer_26
[NBF]root.Data
[NBF]root.Data-preview.png
icons8_package_64
[NBF]root.Data
[NBF]root.Data-preview.png
sDzN
[NBF]root.Data
[NBF]root.Data-preview.png
Btlj
[NBF]root.Data
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙