Malicious
Malicious

b849d44bb2d4e051e9ee7159116d4e71

PE Executable
MD5: b849d44bb2d4e051e9ee7159116d4e71
Size: 1.9 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 b849d44bb2d4e051e9ee7159116d4e71
Sha1 0f0497d2f6b3f6794d61659bb31fa145ab369845
Sha256 3b2d97f6d930500dda7b0d2e9550fe192a8716590a48c00a0e1ebac3a3629db4
Sha384 c4f386213b96d1d65576a1c9334fa042415196f4ad3c71a046bffb80a9df271efffd5ad9e72bf97735ce87cbd4b9e3e9
Sha512 2269886bfade22986d7c84532a5192a92394c1e76aee5507f98b94277f50abed0eb8da6d4fa3aba7aee61da75186b097768a5020f9b95916afcf4534c821d401
SSDeep 49152:wmhyh4qBpSHXUJDsBOuonXMA7GmGZ6kmTe:wmhk4qBY3/oXRymGZPm
TLSH 6B950281A316D807D6941AB48DA0F3B403746FF8ED07C353BEEA7DDBB9193862C58252
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
YN.FA.resources
QsS.SsH.resources
$this.Icon
[NBF]root.IconData
TsQ.Esx.resources
$this.Icon
[NBF]root.IconData
contextMenu.TrayLocation
Bi
[NBF]root.Data
notifyIcon.Icon
[NBF]root.IconData
timer.TrayLocation
notifyIcon.TrayLocation
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Clock.Properties.Resources.resources
gjzP
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
FNhk.exe
Full Name
FNhk.exe
EntryPoint
System.Void ppv.IpV::gpd()
Scope Name
FNhk.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
FNhk
Assembly Version
10.0.26100.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
182
Main Method
System.Void ppv.IpV::gpd()
Main IL Instruction Count
16
Main IL
br IL_000F: nop
call System.Void mtN.atA::phF()
br IL_001A: nop
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002C: nop
nop <null>
newobj System.Void TsQ.Esx::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_002A: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void mtN.atA::phF()
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
YN.FA.resources
QsS.SsH.resources
$this.Icon
[NBF]root.IconData
TsQ.Esx.resources
$this.Icon
[NBF]root.IconData
contextMenu.TrayLocation
Bi
[NBF]root.Data
notifyIcon.Icon
[NBF]root.IconData
timer.TrayLocation
notifyIcon.TrayLocation
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Clock.Properties.Resources.resources
gjzP
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙