Malicious
Malicious

faa3c26f1983cd7f6179ade784f43269

Share on LinkedIn
Print
WSF File
MD5: faa3c26f1983cd7f6179ade784f43269
Size: 12.48 MB
application/xml
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 faa3c26f1983cd7f6179ade784f43269
Sha1 f61e521af2089a4e366a18ffb1bf888c48496978
Sha256 f2fcc2c65878afe01688efe9183a3f30cb13e5a5c822c470412b880a881ba34f
Sha384 5d4722215d3e78cbb4d69634dcd77abf8222bb93027beae6c84d7b076b95102dfa379268693e66dfb1e44c56139bdbba
Sha512 3b8ebb671ce782d41c0903b78312f751a938159787fcca6914002baac1854671d2bd564074840e8a01f9b500c290077142028c2896b88aaed7e3de3d6f98977d
SSDeep 98304:JMVTs3asyuc+KuD3PlxOYoHwfLk3vSmaR0+Mc4AN0edaAHDfysrTlt:JAsKsyfATObAbN0G
TLSH 93C64A8563FC1A35E3B747359970627A05767C2AADC1D78E3A89BA0D3971240FCF0A27
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLUPolyX 0.3 -> delikon
.Net Resources
KjyStrap.g.resources
KjyStrap.Properties.Resources.resources
CancelButton
CancelButton-preview.png
CancelButtonHover
CancelButtonHover-preview.png
DarkCancelButton
DarkCancelButton-preview.png
DarkCancelButtonHover
DarkCancelButtonHover-preview.png
Icon2008
Icon2011
Icon2017
Icon2019
Icon2022
IconEarly2015
IconKjyStrap
IconKjyStrapClassic
IconLate2015
KjyStrap.Resources.Strings.resources
KjyStrap.UI.Elements.Bootstrapper.LegacyDialog2008.resources
KjyStrap.UI.Style.Editor-Theme-Dark.xshd
KjyStrap.UI.Style.Editor-Theme-Light.xshd
KjyStrap.Resources.CustomBootstrapperSchema.json
KjyStrap.Resources.CustomBootstrapperTemplate_Blank.xml
KjyStrap.Resources.CustomBootstrapperTemplate_Simple.xml
KjyStrap.Resources.Mods.Cursor.From2006.ArrowCursor.png
KjyStrap.Resources.Mods.Cursor.From2006.ArrowCursor.png-preview.png
KjyStrap.Resources.Mods.Cursor.From2006.ArrowFarCursor.png
KjyStrap.Resources.Mods.Cursor.From2006.ArrowFarCursor.png-preview.png
KjyStrap.Resources.Mods.Cursor.From2013.ArrowCursor.png
KjyStrap.Resources.Mods.Cursor.From2013.ArrowCursor.png-preview.png
KjyStrap.Resources.Mods.Cursor.From2013.ArrowFarCursor.png
KjyStrap.Resources.Mods.Cursor.From2013.ArrowFarCursor.png-preview.png
KjyStrap.Resources.Mods.Sounds.OldGetUp.mp3
KjyStrap.Resources.Mods.Sounds.OldJump.mp3
KjyStrap.Resources.Mods.Sounds.OldWalk.mp3
KjyStrap.Resources.Mods.Sounds.Empty.mp3
KjyStrap.Resources.Mods.OldAvatarBackground.rbxl
Overlay_96e8af55.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
_RDATA
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path pe:exe>pe:exe>bin
Shape pe:exe>pe:exe>bin
malicious 3 nodes
Path pe:exe>pe:exe>html
Shape pe:exe>pe:exe>html
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_02cc78d3.bin (12210984 bytes)
Info
PDB Path: D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
An error has occurred. This application may no longer respond until reloaded. Reload 🗙