Malicious
Malicious

04f690ebbefd721c72f79d60dc6dc72b

PE Executable
MD5: 04f690ebbefd721c72f79d60dc6dc72b
Size: 56.32 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 04f690ebbefd721c72f79d60dc6dc72b
Sha1 782e3585bc0f1566253c1a2e35fbfc4cbae62e07
Sha256 abd9d912407f5336088a5b5394178df2994377f6738651bf37bc0d6976d0c861
Sha384 06887940c98fa63a6f24d563831e16fd18cf7bc98462ba94d371c0fe23ba655a41b5dddc4860fd6f72aa5fe20e0d152a
Sha512 d33d775a2090d7a089129b15a2334727a0e2175693f0906e8b9079ccb75d3381ca38b4441d0a0c4d18b376204581c2d472fff54e16c5620b6b8e53ceadffa2e1
SSDeep 1536:1cwMDnkSNkNy2OWDBfwsNMD9VXExI3pmRm:pMDnk5ELWDhwsNMDrXExI3pm
TLSH 60431744BFEA4A01E2BD8F3469F655150A34BA63E532EB1F48D568EB13327C58C40FE6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] NjRat huhuhuhuhuhuhuhuhuhuhu
cnc_host [H] 6.tcphuhuhuhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
Anti_CH Fhuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
USB_SP Fhuhuhuhu
is_user_reg [Isu] Thuhuhuhu
cnc_port [P] 1huhuhuhu
reg_key [RG] cbc859huhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] Vihuhuhuhu
version [VR] <- NjRhuhuhuhuhuhuhuhuhuhuhu
splitter [Y] Y262huhuhuhu
MSGE Dihuhuhuhu
MSGT Thhuhuhuhu
MSGB Sorry,huhuhuhuhuhuhuhuhuhuhu
MSGSYM vbChuhuhuhu
OBITO Dihuhuhuhu
TSKE Dihuhuhuhu
TSK Wirehuhuhuhuhuhuhu
KAKASHI Dihuhuhuhu
AKATSUKI Dihuhuhuhu
CLEANSWEEP Dihuhuhuhu
PASTEE Dihuhuhuhu
PASTEBIN https:huhuhuhuhuhuhuhuhuhuhu
CLIP nhuhuhuhu
UAC Dihuhuhuhu
nowifi ohuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
539
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
539
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
CnC CNCmalicious
6.tcphuhuhuhuhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] NjRat huhuhuhuhuhuhuhuhuhuhu
cnc_host [H] 6.tcphuhuhuhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
Anti_CH Fhuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
USB_SP Fhuhuhuhu
is_user_reg [Isu] Thuhuhuhu
cnc_port [P] 1huhuhuhu
reg_key [RG] cbc859huhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] Vihuhuhuhu
version [VR] <- NjRhuhuhuhuhuhuhuhuhuhuhu
splitter [Y] Y262huhuhuhu
MSGE Dihuhuhuhu
MSGT Thhuhuhuhu
MSGB Sorry,huhuhuhuhuhuhuhuhuhuhu
MSGSYM vbChuhuhuhu
OBITO Dihuhuhuhu
TSKE Dihuhuhuhu
TSK Wirehuhuhuhuhuhuhu
KAKASHI Dihuhuhuhu
AKATSUKI Dihuhuhuhu
CLEANSWEEP Dihuhuhuhu
PASTEE Dihuhuhuhu
PASTEBIN https:huhuhuhuhuhuhuhuhuhuhu
CLIP nhuhuhuhu
UAC Dihuhuhuhu
nowifi ohuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
6.tcphuhuhuhuhuhuhu
04f690ebbefd721c72f79d60dc6dc72b
Port PORTmalicious
1huhuhuhu
04f690ebbefd721c72f79d60dc6dc72b
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙