Suspect
PE Executable
MD5: 8ad256c5b786abb5f1552d906df3482a
Size: 4.32 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 8ad256c5b786abb5f1552d906df3482a |
| Sha1 | c321593cb3d8e279dfbdcf6d8bb94fac93cdc405 |
| Sha256 | b3c2f9ac068664bb861d7f8a59db533810032bc26d75fad48dbd0e2ba26413b2 |
| Sha384 | 0cc05215268dd4dbff2a151a6fdef0f54f1811fcea84ba4c39e0e34c73bf81169775489e5ae3a2020db3a2d9cf1af63a |
| Sha512 | 910cc3d3ca11780876d248ef5e9f78ff599838b93d4dc6e6c70d26bc39b6c4194c77d5f5046ebdcbf40f324432fd6fb965fe8bb9b6b263389db8aa7e12e7b7f1 |
| SSDeep | 98304:fIkY/PwAGbn5quMRYfiGmvd0W3qfb+VBO:fdgYAG75qurfiUYESXO |
| TLSH | 7A16AE1BF6748270D0B6C075C5E2AB9AEE7134864B3096CB1285977D3F27AF68639331 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NETUPolyX 0.3 -> delikon
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
Structural branches: 6
STICH kept: 2secondary ignored: 4
bin
4Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:dll>arc:7zsfx
Shape
pe:exe>pe:dll>arc:7zsfx
3 nodes
Path
pe:exe>arc:7zsfx
Shape
pe:exe>arc:7zsfx
2 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Overlay extracted: Overlay_5a095be0.bin (64 bytes) |
| Info | PDB Path: C:\Users\WarGack\source\repos\Installer\obj\Release\Installer.pdb |
| VHD | DiscUtils extraction failed (ArgumentOutOfRangeException) for VHD. |
| VHD | DiskImage extraction mode: RecursiveExtractor fallback (VHD) |
| Module Name | Installer.exe |
| Full Name | Installer.exe |
| EntryPoint | System.Void Installer.Program::Main() |
| Scope Name | Installer.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Installer |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 160 |
| Main Method | System.Void Installer.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |
| Module Name | Installer.exe |
| Full Name | Installer.exe |
| EntryPoint | System.Void Installer.Program::Main() |
| Scope Name | Installer.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Installer |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 160 |
| Main Method | System.Void Installer.Program::Main() |
| Main IL Instruction Count | 10 |
| Main IL | |