Malicious
Malicious

8c21b2fbded2faeb6db2e7a20c513cdb

PE Executable
MD5: 8c21b2fbded2faeb6db2e7a20c513cdb
Size: 97.79 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 8c21b2fbded2faeb6db2e7a20c513cdb
Sha1 38b837cc5fe814ca9580f9029386aa405f8e94df
Sha256 b59653f1e2b8dae784ca4211199d2887ea676d27e7af9d057a625cf9281c17e0
Sha384 32c5f053587359ce84229103cb3ef4432dbe270e18269bb6c9e0867f2668bdde2f1e0265aa69aad8586b91b95d464d73
Sha512 8affc27bee62305eede5205101e457e62f33d137c62c1a1c324399052d1231876dfc7d0148055618044a96f14fe4cbd3ba2428bf3efcf0993fe534c0524a2fe7
SSDeep 1536:5qsCbqDylbG6jejoigIj43Ywzi0Zb78ivombfexv0ujXyyed2z3tmulgS6p8l:XEwiYj+zi0ZbYe1g0ujyzdT8
TLSH 9DA35D3067AC9F19EAFD1B75B4B2012043F0E08A9091FB4A4DC194E71FA7B865957EF2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
[Configuration Module Name] Enthuhuhuhu
[Configuration Module Full Name] Enthuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Happy.exe
Full Name
Happy.exe
EntryPoint
System.Void Program::Main(System.String[])
Scope Name
Happy.exe
Scope Type
ModuleDef
Kind
Console
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Happy
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
234
Main Method
System.Void Program::Main(System.String[])
Main IL Instruction Count
3
Main IL
newobj System.Void EntryPoint::.ctor()
call System.Void Program::Execute(EntryPoint)
ret <null>
Module Name
Happy.exe
Full Name
Happy.exe
EntryPoint
System.Void Program::Main(System.String[])
Scope Name
Happy.exe
Scope Type
ModuleDef
Kind
Console
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Happy
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
234
Main Method
System.Void Program::Main(System.String[])
Main IL Instruction Count
3
Main IL
newobj System.Void EntryPoint::.ctor()
call System.Void Program::Execute(EntryPoint)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
[Configuration Module Name] Enthuhuhuhu
[Configuration Module Full Name] Enthuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙