Malicious
daaee64b59f10f99612425d5ce3d3257
PE Executable
MD5: daaee64b59f10f99612425d5ce3d3257
Size: 1.26 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
High
| MD5 | daaee64b59f10f99612425d5ce3d3257 |
| Sha1 | faa35c579c63e62260d51c7ed8224bb566d2d5c4 |
| Sha256 | 7bf8aac49b4750a112ede1b774271fc108c334fd0d062f98cf6768c99b579340 |
| Sha384 | 8642dbba17aef3220613ef5b9f34fa448efeb775c45497e089a6fbedbafeb8158974e7919f78745177108108f334f645 |
| Sha512 | a2ca9556a43b1c6cff20464ef804f03117e0a8fdda382e2fc5d6157cd7dcb5db3ac3b4eca241ab2b9f81c516f12f7c09d0a2675c59e4de88696421877f8c2961 |
| SSDeep | 24576:NrNDjP/2oSdvS44TmRPPWQMA0lcUlJ1sLdKTXI5UaLYgeLP65ox0eWPxM75cc/VZ:Nhb/2oS0tTmRPPWQb0lHlJ1cdEI5/sLF |
| TLSH | 5B450254321BCD05D0925FB14CA1E7B0117A4F8CD923D607E9FA7EABB93B3576D82282 |
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
3 / 3
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
Path
pe:exe>bin
Shape
pe:exe>bin
malicious
2 nodes
| Name | Value |
|---|---|
| Module Name | JJrm.exe |
| Full Name | JJrm.exe |
| EntryPoint | System.Void vT.oM::Sc() |
| Scope Name | JJrm.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | JJrm |
| Assembly Version | 8.6.4.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 149 |
| Main Method | System.Void vT.oM::Sc() |
| Main IL Instruction Count | 16 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: JJrm.pdb |
No malware configuration was found at this point.
You must be signed in to view YARA rules.