Malicious
Malicious

e989fab5128da2ce5cbbccea75b8b5e1

PE Executable
MD5: e989fab5128da2ce5cbbccea75b8b5e1
Size: 97.79 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 e989fab5128da2ce5cbbccea75b8b5e1
Sha1 f1d72ea6c4d2ddcc5704bab16cbc5e3dd20ec755
Sha256 612150ea6972715f8b79d20aa153e2173bf06ca8d5d99e1d706332de1ae081c4
Sha384 83da30e3006e791dda86a031df36e08e3337fdbef37472f7abd61d97a6e44a2b9eca7445489323f2c438b098753bad64
Sha512 aa28dce9cf046eba9242c8b3bf0a35a498ded50d043f9e3007a7fdb280da99e2d5f507aefdc40f8d1c57a1db1cc4894b0bbef82ba8a47bbba3450d2e6a4aa488
SSDeep 1536:9qs+XqrzWBlbG6jejoigI343Ywzi0Zb78ivombfexv0ujXyyed2v3tmulgS6pY:r0gzWHY3+zi0ZbYe1g0ujyzdXY
TLSH C6A35D3067AC9F19EAFD1B74B4B2012043F0E48A9091FB4B4DC154E61FA7B865957EF2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
[Configuration Module Name] Enthuhuhuhu
[Configuration Module Full Name] Enthuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Happy.exe
Full Name
Happy.exe
EntryPoint
System.Void Program::Main(System.String[])
Scope Name
Happy.exe
Scope Type
ModuleDef
Kind
Console
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Happy
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
234
Main Method
System.Void Program::Main(System.String[])
Main IL Instruction Count
3
Main IL
newobj System.Void EntryPoint::.ctor()
call System.Void Program::Execute(EntryPoint)
ret <null>
Module Name
Happy.exe
Full Name
Happy.exe
EntryPoint
System.Void Program::Main(System.String[])
Scope Name
Happy.exe
Scope Type
ModuleDef
Kind
Console
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Happy
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
234
Main Method
System.Void Program::Main(System.String[])
Main IL Instruction Count
3
Main IL
newobj System.Void EntryPoint::.ctor()
call System.Void Program::Execute(EntryPoint)
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
[Configuration Module Name] Enthuhuhuhu
[Configuration Module Full Name] Enthuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙