Symbol Obfuscation Score
|
Hash | Hash Value |
|---|---|
| MD5 | 057f2aa175054b47c34d052bf466d6ff
|
| Sha1 | 74009dddca0e11bf8e152c45edc801da1932dc23
|
| Sha256 | 1b72bd4af0ebae9f4939c1a0d3d8f4d95f0a17575d8ef882334018e5b080ab10
|
| Sha384 | 9b09b2d9f3a635ffad45c5f3ffe9b2993e334d5522f892312dcd92a306a9869abca18b693ef028e97cc3e38f0f581b23
|
| Sha512 | 29755bd25d5af348c861c8006cbcc8c9672f89892dc8c6c98f982fc75edcba235d31175d7b7c1ef670e1c635c8287470b3118ed370aaf2cf8be785441daa0e84
|
| SSDeep | 6144:QRbUNURygiHV0LkNjejZd0MMu5yRbUNURy4bSIIozksYPL4KJlsLGW4fz:xUROHVMkydpMupURZbnzWDw+
|
| TLSH | 67E44C44B649DEA5E8064170CC29D1F21914BDAADA50614F39ECFF3FFAB3749100DEAA
|
PeID
|
Config. Field0 | Value |
|---|---|
| victim_name [VN] | |
| version [VR] | 0.7d |
| executable_name [EXE] | server.exe |
| directory [DR] | TEMP |
| reg_key [RG] | 19b66d84454507de29ccf25e3f94af15 |
| cnc_host [H] | detetive.ddns.net |
| cnc_port [P] | 2020 |
| splitter [Y] | |'|'| |
| BD [BD] | False |
| is_dir_defined [Idr] | False |
| is_startup_folder [IsF] | False |
| is_user_reg [Isu] | False |
| reg_path [sf] | Software\Microsoft\Windows\CurrentVersion\Run |
| packet_size [b] | 5121 |
|
Name0 | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | Authenticode present at 0x97400 size 58120 bytes |
| Module Name | j.exe |
| Full Name | j.exe |
| EntryPoint | System.Void j.A::main() |
| Scope Name | j.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | j |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 214 |
| Main Method | System.Void j.A::main() |
| Main IL Instruction Count | 2 |
| Main IL | call System.Void j.OK::ko() ret <null> |
| Module Name | j.exe |
| Full Name | j.exe |
| EntryPoint | System.Void j.A::main() |
| Scope Name | j.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | j |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 214 |
| Main Method | System.Void j.A::main() |
| Main IL Instruction Count | 2 |
| Main IL | call System.Void j.OK::ko() ret <null> |
|
Name0 | Value |
|---|---|
| CnC | detetive.ddns.net |
| Port | 2020 |
|
Config. Field0 | Value |
|---|---|
| victim_name [VN] | |
| version [VR] | 0.7d |
| executable_name [EXE] | server.exe |
| directory [DR] | TEMP |
| reg_key [RG] | 19b66d84454507de29ccf25e3f94af15 |
| cnc_host [H] | detetive.ddns.net |
| cnc_port [P] | 2020 |
| splitter [Y] | |'|'| |
| BD [BD] | False |
| is_dir_defined [Idr] | False |
| is_startup_folder [IsF] | False |
| is_user_reg [Isu] | False |
| reg_path [sf] | Software\Microsoft\Windows\CurrentVersion\Run |
| packet_size [b] | 5121 |
|
Name0 | Value | Location |
|---|---|---|
| CnC | detetive.ddns.net Malicious |
057f2aa175054b47c34d052bf466d6ff |
| Port | 2020 Malicious |
057f2aa175054b47c34d052bf466d6ff |