Malicious
PE Executable
MD5: 00c068f474ba7b8b74cdde575c904a29
Size: 36.35 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 00c068f474ba7b8b74cdde575c904a29 |
| Sha1 | 821b8dca8008131def8f3a21b06016326218d423 |
| Sha256 | 20314d83a7ca048d0ff425c664deaac72fb18ae6a29c465ab2ed24c6abf4c96d |
| Sha384 | 98b6541c87205d2370bad3324ddd52bd06faa3607170ce63e10a7b1e8a1cf1917823f3c3fbdc1fde79059327564bb687 |
| Sha512 | 48f18d456e7bc47c2dfb5a32112f5577ccc2210967bcedb6433ca8c28a1e0f25b1efbe7d16fedaccf0f82974dcf517a2ddd9825ecdc4f11f89c306445ea4358d |
| SSDeep | 768:cagcDbkCPEfknzDc8ZTRmiYF898ISOjhPfZt:ca1kRMnznAF898JOjVZt |
| TLSH | 9DF24C4477A04622DAFF6FB65DF352020274A917D913EF6E0CE945DB2B67AC48B003E6 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
| Config. Field | Value |
|---|---|
| Mutex | pGOibhuhuhuhuhuhuhu |
| Hosts | 127.0.huhuhuhuhuhuhu |
| Port | 1huhuhuhu |
| KEY | <12huhuhuhu |
| USBNM | <Xwhuhuhuhu |
| family | xhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | antivm.exe |
| Full Name | antivm.exe |
| EntryPoint | System.Void Stub.Main::Main() |
| Scope Name | antivm.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | antivm |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 183 |
| Main Method | System.Void Stub.Main::Main() |
| Main IL Instruction Count | 74 |
| Main IL | |
| Module Name | antivm.exe |
| Full Name | antivm.exe |
| EntryPoint | System.Void Stub.Main::Main() |
| Scope Name | antivm.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | antivm |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 183 |
| Main Method | System.Void Stub.Main::Main() |
| Main IL Instruction Count | 74 |
| Main IL | |
Mutex
MUTEXmalicious
pGOibhuhuhuhuhuhuhu
CnC
CNCmalicious
127huhuhuhu
CnC
CNCmalicious
160.1huhuhuhuhuhuhu
Port
PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential