Malicious
Malicious

0f74892809973a93321c7ba05bdf61ca

Share on LinkedIn
Print
PE Executable
MD5: 0f74892809973a93321c7ba05bdf61ca
Size: 32.26 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 0f74892809973a93321c7ba05bdf61ca
Sha1 d0b31bfd1d8e40efc3b3b30c1cf9b655c9365935
Sha256 03d2e8ef968a70c032ffb01c98b29ab612ae48043b44e63d15c2504f7f85de13
Sha384 2baffc9ae6744276aa1ed09c599a51f8932ff773d0b87544d8a4ce392177c5d8c330571a0dd90a1c4daaa47a5651128b
Sha512 2bf2646c3e62966560a4a293ce72d18516bf13be31f0aa4c4705027efe11580f9bc1236114edd845a6678c11a8d6d02b5c60eb6f3d37a0d66d696bbac0cae9a5
SSDeep 768:mRCLqdzNB0zx/6LyTmvUXdvMxQmIDUu0ti6Qj:R6KbpIQVkyj
TLSH C4E22AADFBE64465D2BD0AB50571950013B8E003E523F77E4ECB24E62B6B6D84B84DF2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] Windowhuhuhuhuhuhuhu
cnc_host [H] fly88huhuhuhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
Anti_CH Fhuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
USB_SP Thuhuhuhu
is_user_reg [Isu] Thuhuhuhu
cnc_port [P] 4huhuhuhu
reg_key [RG] 6d390chuhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] flyhuhuhuhu
version [VR] 0huhuhuhu
splitter [Y] Y262huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
241
Main Method
System.Void j.A::main()
Main IL Instruction Count
4
Main IL
nop <null>
call System.Void j.OK::ko()
nop <null>
ret <null>
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
241
Main Method
System.Void j.A::main()
Main IL Instruction Count
4
Main IL
nop <null>
call System.Void j.OK::ko()
nop <null>
ret <null>
CnC CNCmalicious
fly88huhuhuhuhuhuhu
Port PORTmalicious
4huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙