Malicious
caf6ccdae819b91fa4c9c17c14a161f5
PE Executable
MD5: caf6ccdae819b91fa4c9c17c14a161f5
Size: 1.7 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
High
| MD5 | caf6ccdae819b91fa4c9c17c14a161f5 |
| Sha1 | 23f333ad78abbfb012040430cb7cb57e877be650 |
| Sha256 | 0f5e6fbd1e12c2653146c7c18cb55c7e4f9d7e241f299d323a3caf12c13c7727 |
| Sha384 | 81f48e8d8172b438077cea4dfc64380d8721e77ba628b0303b104caff1f14bff6a34d84849fe03b6171f2128dbe7c698 |
| Sha512 | ad0bce742f68ec2eca7db87124f5416d62dd6bcd3ada0d7966fb177e9416ccc9d47bd6b70e0a5315006277629ca910a6da0f28c951a611ea9d593faad7b5c8e5 |
| SSDeep | 49152:9fb/2oSqoxtJmAFLV67iuAVwXgNjqmDb76la1Yvhdl:9fbuoefHLU7iuAWAqmDyAUj |
| TLSH | BA75121C5107D902D2965F740DF1E3B426B48F84A902C747DEEEBEEBF57A3992E41282 |
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
4 / 4
Path
pe:exe>pe:rsrc>img
Shape
pe:exe>pe:rsrc>img
malicious
3 nodes
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: iyAS.pdb |
| Module Name | iyAS.exe |
| Full Name | iyAS.exe |
| EntryPoint | System.Void bZ.oE::rC() |
| Scope Name | iyAS.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | iyAS |
| Assembly Version | 8.6.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 149 |
| Main Method | System.Void bZ.oE::rC() |
| Main IL Instruction Count | 16 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.