Malicious
Malicious

8c21b2fbded2faeb6db2e7a20c513cdb

Share on LinkedIn
Print
PE Executable
MD5: 8c21b2fbded2faeb6db2e7a20c513cdb
Size: 97.79 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 8c21b2fbded2faeb6db2e7a20c513cdb
Sha1 38b837cc5fe814ca9580f9029386aa405f8e94df
Sha256 b59653f1e2b8dae784ca4211199d2887ea676d27e7af9d057a625cf9281c17e0
Sha384 32c5f053587359ce84229103cb3ef4432dbe270e18269bb6c9e0867f2668bdde2f1e0265aa69aad8586b91b95d464d73
Sha512 8affc27bee62305eede5205101e457e62f33d137c62c1a1c324399052d1231876dfc7d0148055618044a96f14fe4cbd3ba2428bf3efcf0993fe534c0524a2fe7
SSDeep 1536:5qsCbqDylbG6jejoigIj43Ywzi0Zb78ivombfexv0ujXyyed2z3tmulgS6p8l:XEwiYj+zi0ZbYe1g0ujyzdT8
TLSH 9DA35D3067AC9F19EAFD1B75B4B2012043F0E08A9091FB4A4DC194E71FA7B865957EF2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
[Configuration Module Name] Enthuhuhuhu
[Configuration Module Full Name] Enthuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Happy.exe
Full Name
Happy.exe
EntryPoint
System.Void Program::Main(System.String[])
Scope Name
Happy.exe
Scope Type
ModuleDef
Kind
Console
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Happy
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
234
Main Method
System.Void Program::Main(System.String[])
Main IL Instruction Count
3
Main IL
newobj System.Void EntryPoint::.ctor()
call System.Void Program::Execute(EntryPoint)
ret <null>
Module Name
Happy.exe
Full Name
Happy.exe
EntryPoint
System.Void Program::Main(System.String[])
Scope Name
Happy.exe
Scope Type
ModuleDef
Kind
Console
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Happy
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
234
Main Method
System.Void Program::Main(System.String[])
Main IL Instruction Count
3
Main IL
newobj System.Void EntryPoint::.ctor()
call System.Void Program::Execute(EntryPoint)
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙