Malicious
Malicious

d4ae55ca8185d3406cb7d434eb3818d4

PE Executable
MD5: d4ae55ca8185d3406cb7d434eb3818d4
Size: 1.17 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 d4ae55ca8185d3406cb7d434eb3818d4
Sha1 8f47066dc34a946dbecc503e26409ff7356ccec8
Sha256 1ab8e5c4349478692324199556f19ae3d2d7fa036b70df6ac231a54eb58e14fd
Sha384 6ee58027bc1cdbb7faba95c574534bd78331f7bc2341ac6474302873a835919b736aaf81d3915297310aed7226d338ac
Sha512 83fe566f2402f4b513ee4d0b2ca6805ed2a01d75236cc689d9a1c422c0d926a504b8f6e56d005d0d3de46042dba2b1dbf4fd0b54d5a1435c1284b768465cb1b0
SSDeep 24576:ZR1jP/2oSdvrPibgVLldYEwCX3jbpcS0T6U98/zI6mZ3/R5PKxn:Znb/2oStOg/dTwCnjdU0K/5+n
TLSH 904501586217CD11C1D60E7148E1D7F412B48F84EA12C707AAFABEEB783B35A3D552C6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ITF.vTe.resources
$this.Icon
[NBF]root.IconData
Pro
[NBF]root.Data
backgroundWorker1.TrayLocation
lTx.yTB.resources
GT8.qTk.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
NeuralLinkDataMiner.Properties.Resources.resources
qrFb
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Module Name
jdXg.exe
Full Name
jdXg.exe
EntryPoint
System.Void je.mS::bl()
Scope Name
jdXg.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jdXg
Assembly Version
8.6.4.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: jdXg.pdb
Total Strings
149
Main Method
System.Void je.mS::bl()
Main IL Instruction Count
16
Main IL
br IL_0017: nop
nop <null>
newobj System.Void ITF.vTe::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0015: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002C: nop
call System.Void ImP.Mmc::vVD()
br IL_0005: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0022: call System.Void ImP.Mmc::vVD()
Module Name
jdXg.exe
Full Name
jdXg.exe
EntryPoint
System.Void je.mS::bl()
Scope Name
jdXg.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jdXg
Assembly Version
8.6.4.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
149
Main Method
System.Void je.mS::bl()
Main IL Instruction Count
16
Main IL
br IL_0017: nop
nop <null>
newobj System.Void ITF.vTe::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_0015: nop
nop <null>
ret <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_002C: nop
call System.Void ImP.Mmc::vVD()
br IL_0005: nop
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0022: call System.Void ImP.Mmc::vVD()
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
ITF.vTe.resources
$this.Icon
[NBF]root.IconData
Pro
[NBF]root.Data
backgroundWorker1.TrayLocation
lTx.yTB.resources
GT8.qTk.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
NeuralLinkDataMiner.Properties.Resources.resources
qrFb
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙