Malicious
Malicious

f651e9225960daeb8dfb96c3da275294

PE Executable
MD5: f651e9225960daeb8dfb96c3da275294
Size: 979.97 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 f651e9225960daeb8dfb96c3da275294
Sha1 34b5e8d7449ce558ec9aafc624e996844614a614
Sha256 cb8d68041200958ef7c8b1c5d5cb82c2545f2d89b67dd49c564242f2f009362c
Sha384 6ea45f3f8188255130e3a49245b0d121f83664e1d30c41b05ad7f7c00d849e22b8242168af6a82dab5dbac8596502ead
Sha512 8cfc7a3778fe2bcd77f50d503e155b4b19d1e1c7d98c9f32767e4cf6f795d4b51102bb9842bc7faa2bda5810a88b32c5ec51b3168e65688e5d2175fa99adbbe0
SSDeep 24576:enODWmdY07kLqqUIgHYBzGZboBpMPQUeKRWD0Uy88PwPl:2KY0djIEYBzgborMPRRdUy8
TLSH 362522A157EAC117C548033159E2E37203B8CE88F963DA6B5FDDAEC7B92375A5C41382
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
nT3.iTV.resources
$this.Icon
[NBF]root.IconData
MR5
[NBF]root.Data
dT1.zTX.resources
NzuI.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
GalacticEmpire4X.Properties.Resources.resources
sOcj
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
4 / 4
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: NzuI.pdb
Module Name
NzuI.exe
Full Name
NzuI.exe
EntryPoint
System.Void yR.kh::Qr()
Scope Name
NzuI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NzuI
Assembly Version
4.2.6.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
69
Main Method
System.Void yR.kh::Qr()
Main IL Instruction Count
16
Main IL
br IL_001D: nop
call System.Void rCp.ACL::hqv()
br IL_0028: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void rCp.ACL::hqv()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0011: nop
nop <null>
newobj System.Void nT3.iTV::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000F: nop
Module Name
NzuI.exe
Full Name
NzuI.exe
EntryPoint
System.Void yR.kh::Qr()
Scope Name
NzuI.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
NzuI
Assembly Version
4.2.6.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
69
Main Method
System.Void yR.kh::Qr()
Main IL Instruction Count
16
Main IL
br IL_001D: nop
call System.Void rCp.ACL::hqv()
br IL_0028: nop
nop <null>
ret <null>
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_0005: call System.Void rCp.ACL::hqv()
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0011: nop
nop <null>
newobj System.Void nT3.iTV::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_000F: nop
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
nT3.iTV.resources
$this.Icon
[NBF]root.IconData
MR5
[NBF]root.Data
dT1.zTX.resources
NzuI.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
GalacticEmpire4X.Properties.Resources.resources
sOcj
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙