Malicious
Malicious

e989fab5128da2ce5cbbccea75b8b5e1

Share on LinkedIn
Print
PE Executable
MD5: e989fab5128da2ce5cbbccea75b8b5e1
Size: 97.79 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 e989fab5128da2ce5cbbccea75b8b5e1
Sha1 f1d72ea6c4d2ddcc5704bab16cbc5e3dd20ec755
Sha256 612150ea6972715f8b79d20aa153e2173bf06ca8d5d99e1d706332de1ae081c4
Sha384 83da30e3006e791dda86a031df36e08e3337fdbef37472f7abd61d97a6e44a2b9eca7445489323f2c438b098753bad64
Sha512 aa28dce9cf046eba9242c8b3bf0a35a498ded50d043f9e3007a7fdb280da99e2d5f507aefdc40f8d1c57a1db1cc4894b0bbef82ba8a47bbba3450d2e6a4aa488
SSDeep 1536:9qs+XqrzWBlbG6jejoigI343Ywzi0Zb78ivombfexv0ujXyyed2v3tmulgS6pY:r0gzWHY3+zi0ZbYe1g0ujyzdXY
TLSH C6A35D3067AC9F19EAFD1B74B4B2012043F0E48A9091FB4B4DC154E61FA7B865957EF2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
[Configuration Module Name] Enthuhuhuhu
[Configuration Module Full Name] Enthuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Happy.exe
Full Name
Happy.exe
EntryPoint
System.Void Program::Main(System.String[])
Scope Name
Happy.exe
Scope Type
ModuleDef
Kind
Console
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Happy
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
234
Main Method
System.Void Program::Main(System.String[])
Main IL Instruction Count
3
Main IL
newobj System.Void EntryPoint::.ctor()
call System.Void Program::Execute(EntryPoint)
ret <null>
Module Name
Happy.exe
Full Name
Happy.exe
EntryPoint
System.Void Program::Main(System.String[])
Scope Name
Happy.exe
Scope Type
ModuleDef
Kind
Console
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Happy
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
234
Main Method
System.Void Program::Main(System.String[])
Main IL Instruction Count
3
Main IL
newobj System.Void EntryPoint::.ctor()
call System.Void Program::Execute(EntryPoint)
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙