Malicious
PE Executable
MD5: c0012e2038696947332148f699ab3a78
Size: 1.32 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | c0012e2038696947332148f699ab3a78 |
| Sha1 | e642d4d0b085dea2394eeb017db2db8a160df731 |
| Sha256 | b4e22e21e205559a595d1e3b47516079d19bf9c226d41023494ed07f41648e65 |
| Sha384 | 5bb32526b9843f78104318caa1a3f934cc3d62a8ea3a2299b98f0147fcc37630ab20ee0dbd30e9ccfda8e3df2ef479fa |
| Sha512 | 4aa93829d8672c5e24173b2c0dd6bbfddd73bdb3d3ddf007df4d3f0ed23d81532714524ef56ea6c3951c8069c355f964328c9f559504e688d241fb20af452e8d |
| SSDeep | 24576:+EzaqFeNvotX6CwcAGe59gZrp4CYuMw4dv2SM:+EaqeaXPAGeQZOxM |
| TLSH | AC551224B75BEC03D5B123318AE0E2B517B6AE4DE522C25B5FEA1DE73912BD158C0393 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
3 / 3
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
Path
pe:exe>bin
Shape
pe:exe>bin
malicious
2 nodes
| Name | Value |
|---|---|
| Module Name | HSsZ.exe |
| Full Name | HSsZ.exe |
| EntryPoint | System.Void aI.Fi::bu() |
| Scope Name | HSsZ.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | HSsZ |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 417 |
| Main Method | System.Void aI.Fi::bu() |
| Main IL Instruction Count | 16 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | HSsZ.exe |
| Full Name | HSsZ.exe |
| EntryPoint | System.Void aI.Fi::bu() |
| Scope Name | HSsZ.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | HSsZ |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5 |
| Total Strings | 417 |
| Main Method | System.Void aI.Fi::bu() |
| Main IL Instruction Count | 16 |
| Main IL | |