Malicious
Malicious

bc1239e04ce9419fac4724bc9d8e996c

PE Executable
MD5: bc1239e04ce9419fac4724bc9d8e996c
Size: 407.04 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 bc1239e04ce9419fac4724bc9d8e996c
Sha1 f584df6373c3527771c1dd61c4b382c65294e9a3
Sha256 e5dbac50755b3dba5237bf6f9d4c42ce965dbee297c9991e261e86bde0b5a511
Sha384 52658838f416cc0dc2a97f5fb5731072beb55faa390bf289807afecd008dd70c6746947878393d049028fb5e524397ee
Sha512 f4e851acd1612faaa43457bf248fe18be17a9c70576cbc6b636f819689d9f481965f50bd08e8506f5470487568b8220e78bf3a4177dbc7d4f20de8f3205db685
SSDeep 6144:6M03heac9tb9kyfY8tVy2RGcuQIjB9GTF5COn1XCAPN6iEtMK4f4:f03v8ZfRfjRhuQWm59pCAP+tGf4
TLSH 6384BE0BBA944B01C7956671C4D79C3003E6A98B3733CB9D3F4912DA5C823B9BD4BB99
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
IterableMember.SummarizerMember
TokenAllocator.ContainerSingleton
ExpandableMember.MemberObject
ModularMember.DividedMember
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:dll>pe:rsrc>bin
Shape pe:dll>pe:rsrc>bin
malicious 3 nodes
Path pe:dll>bin
Shape pe:dll>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: Zinqolam.pdb
Module Name
Zinqolam.dll
Full Name
Zinqolam.dll
Scope Name
Zinqolam.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Zinqolam
Assembly Version
2.5.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
46
Main Method
Not found or no body
Module Name
Zinqolam.dll
Full Name
Zinqolam.dll
Scope Name
Zinqolam.dll
Scope Type
ModuleDef
Kind
Dll
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Zinqolam
Assembly Version
2.5.2.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.6
Total Strings
46
Main Method
Not found or no body
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
IterableMember.SummarizerMember
TokenAllocator.ContainerSingleton
ExpandableMember.MemberObject
ModularMember.DividedMember
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙