Malicious
Malicious

9109c033abc7dbffe4d348f4616f9283

Share on LinkedIn
Print
PE Executable
MD5: 9109c033abc7dbffe4d348f4616f9283
Size: 1.2 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 9109c033abc7dbffe4d348f4616f9283
Sha1 2a102ae95883e4c93cf6f4c00f174577d08ca4a8
Sha256 791c4a24330243b233d49a79e43612c54ccece5e04669286fed2673492278ec3
Sha384 af86b5592f666c8976e9d4560b9aa2fda76d48c97ba2fb346141ac01c6c8a27f4f9e351c33022e992fb97e8830a47b12
Sha512 fad5fcb4ba11b3470f5db7472ad72bc94389cf6a7608cb044bf4f41f3e5046b79ffd95f3d662e1a26213e050d302f7fcd8975c545b82a9c9a455e0497cb38136
SSDeep 24576:0BNzHjP/2oSdvSGj1BlRs7R3R4oUXcZRb5xFr0sAZ7ysFHtRiyLYNb:07b/2oSrjbcZnZRbTFAxeb
TLSH A645E0141666CD02D5E65AB4C8E0E2FF41B05E87E912F6439AE97D9FB436385FB802C3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
Sb.Yq.resources
WlC.clw.resources
$this.Icon
[NBF]root.IconData
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
HydroReservoir.Properties.Resources.resources
Pro
[NBF]root.Data
JjCL
[NBF]root.Data
[NBF]root.Data-preview.png
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Module Name
SkNk.exe
Full Name
SkNk.exe
EntryPoint
System.Void JD.fs::j9()
Scope Name
SkNk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
SkNk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void JD.fs::j9()
Main IL Instruction Count
15
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_000B: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0029: call System.Void dLG.Jlz::ryu()
nop <null>
ret <null>
nop <null>
newobj System.Void Sb.Yq::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0017: nop
call System.Void dLG.Jlz::ryu()
br IL_0019: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
SkNk.exe
Full Name
SkNk.exe
EntryPoint
System.Void JD.fs::j9()
Scope Name
SkNk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
SkNk
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
395
Main Method
System.Void JD.fs::j9()
Main IL Instruction Count
15
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_000B: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0029: call System.Void dLG.Jlz::ryu()
nop <null>
ret <null>
nop <null>
newobj System.Void Sb.Yq::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0017: nop
call System.Void dLG.Jlz::ryu()
br IL_0019: nop
An error has occurred. This application may no longer respond until reloaded. Reload 🗙