Malicious
Malicious

122dd982c56a9afb87a9c31e057ae39c

PE Executable
|
MD5: 122dd982c56a9afb87a9c31e057ae39c
|
Size: 121.86 KB
|
application/x-dosexec

Infection Chain
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

Low

Hash
Hash Value
MD5
122dd982c56a9afb87a9c31e057ae39c
Sha1
6efde7881838c1988e0e92f39958f98cc829785d
Sha256
9de2d029ed9820365edfee67a095513aef305825f665e0acc0dbc56081252c9c
Sha384
969c8c06340e9bcf243c7ef6857e2fc3e5dd4bbc7b153967cb43840207f84ba1e374356eab110f1f53daf3d2363fd0b2
Sha512
f2b2fcc9cc62b2ac52b1ed306d6c447ef476aa728a54264d43baaea0955826283b40e5bac589ff3dac7fbcd97406a405e3364609865b2e2968ec60f293b286da
SSDeep
1536:9N+l2bbJOQhVdMc4YIUbzh9mhPwuZxrq7JjWupqKmY7:9A2fJOQe4IUbzChk7JKdz
TLSH
3FC3F601E798C495E059397AADF24590C6B6FD7A6815D60B2C8C75CBABFBF8004423EF

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
Private EXE Protector V2.30-V2.3X -> SetiSoft Team
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:0-preview.png
ID:000A
ID:0
ID:000B
ID:0
ID:000C
ID:0
ID:000D
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Malware Configuration - DcRat config.
Config. Field
Value
Key (AES_256)

V3RnMHl2dllHRjVseGFEbTZQUVdhSm9Ib2dyMEl4WkU=

Ports

56595,6677

Hosts

127.0.0.1,center-mpeg.gl.at.ply.

Version

Install

false

Install-Folder

%AppData%

Install File

�

Mutex

弗שΕPkתi吉ΕGl迪Γץ7DvSΖ

Certificate

MIICKTCCAZKgAwIBAgIVAKDzlSNjJN+HkD60ACvOevgv6c5xMA0GCSqGSIb3DQEBDQUAMF0xDjAMBgNVBAMMBUVCT0xBMRMwEQYDVQQLDApxd3FkYW5jaHVuMRwwGgYDVQQKDBNEY1JhdCBCeSBxd3FkYW5jaHVuMQswCQYDVQQHDAJTSDELMAkGA1UEBhMCQ04wHhcNMjQxMDI3MDE0MDI0WhcNMzUwODA2MDE0MDI0WjAQMQ4wDAYDVQQDDAVEY1JhdDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAnNbWPTWgHgK8tadvgurWY6yksP2Lf+Z5DN7ATl5v1cVDfYH9D5kWBhXhjmHFc/MvoI01DLmL4x7g9gkl6uwDL0NJpS47uaRcNTAtoLLQzSL2/enwHDn2SfdjMsLIFFeRKyAicWM/cy1YsIA/UIBaBrGb7c+Fd9xJS2V2hroWeI0CAwEAAaMyMDAwHQYDVR0OBBYEFLHVij11NCmhsyxuKtByHiIQJyKsMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQENBQADgYEAgBOGuT5bLAqfkghzSrmEV3D/LzeotR3TXXfbd4lPY3V9s8RcLj+8ltcfYk7wXV5tj0xxuaMCGuYjrU8JBfVCFxWCp7h8M75mRvj7GqAoiaIO9sbOtf/qKPvnF7Ni4M3fbF1vGe2rvK4mKFjPLYiuBcUkxdZR9CyMyCDm

ServerSignature

fLuO5tShtui06Dvkul+3GwzraNnyWR7/v4T/bI0cWFGNc9MUZIUBr3xYenJDm4rGaGQ4BpSXLNnNTuQimii10P5KBRxKzBGCSIVuxF4IdzYglfeQiDnh78/X0krcjSwUwtW5/q/dJJmD7LtZCOzdQ6MNez/OD2nb

Anti-VM

null

PasteBin

false

BDOS

1

Delay

Default

Group

false

Informations
Name
Value
Module Name

nigggggggggaaaaaaaaaa.exe

Full Name

nigggggggggaaaaaaaaaa.exe

EntryPoint

System.Void Client.Program::Main()

Scope Name

nigggggggggaaaaaaaaaa.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

nigggggggggaaaaaaaaaa

Assembly Version

3.6.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

163

Main Method

System.Void Client.Program::Main()

Main IL Instruction Count

77

Main IL

ldc.i4.0 <null> stloc.0 <null> br IL_0015: ldloc.0 ldc.i4 1000 call System.Void System.Threading.Thread::Sleep(System.Int32) ldloc.0 <null> ldc.i4.1 <null> add <null> stloc.0 <null> ldloc.0 <null> ldsfld System.String Client.Settings::De_lay call System.Int32 System.Convert::ToInt32(System.String) blt.s IL_0007: ldc.i4 1000 call System.Boolean Client.Settings::InitializeSettings() brtrue IL_0032: nop ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> ldsfld System.String Client.Settings::An_ti call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0047: leave IL_0052 call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis() leave IL_0052: call System.Void Client.Helper.A::B() pop <null> leave IL_0052: call System.Void Client.Helper.A::B() call System.Void Client.Helper.A::B() call System.Boolean Client.Helper.MutexControl::CreateMutex() brtrue IL_0067: leave IL_0072 ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave IL_0072: nop pop <null> leave IL_0072: nop nop <null> ldsfld System.String Client.Settings::Anti_Process call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0087: leave IL_0092 call System.Void Client.Helper.Bjifos::StartBlock() leave IL_0092: nop pop <null> leave IL_0092: nop nop <null> ldsfld System.String Client.Settings::BS_OD call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_00B1: leave IL_00BC call System.Boolean Client.Helper.Mesth4ods::IsAdmin() brfalse IL_00B1: leave IL_00BC call System.Void Client.Helper.ProdfceassC1sritical::Set() leave IL_00BC: nop pop <null> leave IL_00BC: nop nop <null> ldsfld System.String Client.Settings::In_stall call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_00D1: leave IL_00DC call System.Void Client.Install.NormalStartup::Install() leave IL_00DC: call System.Void Client.Helper.Mesth4ods::PreventSleep() pop <null> leave IL_00DC: call System.Void Client.Helper.Mesth4ods::PreventSleep() call System.Void Client.Helper.Mesth4ods::PreventSleep() call System.Boolean Client.Helper.Mesth4ods::IsAdmin() brfalse IL_00F0: leave IL_00FB call System.Void Client.Helper.Mesth4ods::ClearSetting() leave IL_00FB: nop pop <null> leave IL_00FB: nop nop <null> call System.Boolean Client.Connection.ClientSocket::get_IsConnected() brtrue IL_0110: leave IL_011B call System.Void Client.Connection.ClientSocket::Reconnect() call System.Void Client.Connection.ClientSocket::InitializeClient() leave IL_011B: ldc.i4 5000 pop <null> leave IL_011B: ldc.i4 5000 ldc.i4 5000 call System.Void System.Threading.Thread::Sleep(System.Int32) br.s IL_00FB: nop

Module Name

nigggggggggaaaaaaaaaa.exe

Full Name

nigggggggggaaaaaaaaaa.exe

EntryPoint

System.Void Client.Program::Main()

Scope Name

nigggggggggaaaaaaaaaa.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

nigggggggggaaaaaaaaaa

Assembly Version

3.6.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

163

Main Method

System.Void Client.Program::Main()

Main IL Instruction Count

77

Main IL

ldc.i4.0 <null> stloc.0 <null> br IL_0015: ldloc.0 ldc.i4 1000 call System.Void System.Threading.Thread::Sleep(System.Int32) ldloc.0 <null> ldc.i4.1 <null> add <null> stloc.0 <null> ldloc.0 <null> ldsfld System.String Client.Settings::De_lay call System.Int32 System.Convert::ToInt32(System.String) blt.s IL_0007: ldc.i4 1000 call System.Boolean Client.Settings::InitializeSettings() brtrue IL_0032: nop ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> ldsfld System.String Client.Settings::An_ti call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0047: leave IL_0052 call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis() leave IL_0052: call System.Void Client.Helper.A::B() pop <null> leave IL_0052: call System.Void Client.Helper.A::B() call System.Void Client.Helper.A::B() call System.Boolean Client.Helper.MutexControl::CreateMutex() brtrue IL_0067: leave IL_0072 ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) leave IL_0072: nop pop <null> leave IL_0072: nop nop <null> ldsfld System.String Client.Settings::Anti_Process call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_0087: leave IL_0092 call System.Void Client.Helper.Bjifos::StartBlock() leave IL_0092: nop pop <null> leave IL_0092: nop nop <null> ldsfld System.String Client.Settings::BS_OD call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_00B1: leave IL_00BC call System.Boolean Client.Helper.Mesth4ods::IsAdmin() brfalse IL_00B1: leave IL_00BC call System.Void Client.Helper.ProdfceassC1sritical::Set() leave IL_00BC: nop pop <null> leave IL_00BC: nop nop <null> ldsfld System.String Client.Settings::In_stall call System.Boolean System.Convert::ToBoolean(System.String) brfalse IL_00D1: leave IL_00DC call System.Void Client.Install.NormalStartup::Install() leave IL_00DC: call System.Void Client.Helper.Mesth4ods::PreventSleep() pop <null> leave IL_00DC: call System.Void Client.Helper.Mesth4ods::PreventSleep() call System.Void Client.Helper.Mesth4ods::PreventSleep() call System.Boolean Client.Helper.Mesth4ods::IsAdmin() brfalse IL_00F0: leave IL_00FB call System.Void Client.Helper.Mesth4ods::ClearSetting() leave IL_00FB: nop pop <null> leave IL_00FB: nop nop <null> call System.Boolean Client.Connection.ClientSocket::get_IsConnected() brtrue IL_0110: leave IL_011B call System.Void Client.Connection.ClientSocket::Reconnect() call System.Void Client.Connection.ClientSocket::InitializeClient() leave IL_011B: ldc.i4 5000 pop <null> leave IL_011B: ldc.i4 5000 ldc.i4 5000 call System.Void System.Threading.Thread::Sleep(System.Int32) br.s IL_00FB: nop

Artefacts
Name
Value
Key (AES_256)

V3RnMHl2dllHRjVseGFEbTZQUVdhSm9Ib2dyMEl4WkU=

Ports

56595

Ports

6677

CnC

127.0.0.1

CnC

center-mpeg.gl.at.ply.

Mutex

弗שΕPkתi吉ΕGl迪Γץ7DvSΖ

122dd982c56a9afb87a9c31e057ae39c (121.86 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:0-preview.png
ID:000A
ID:0
ID:000B
ID:0
ID:000C
ID:0
ID:000D
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Characteristics
Malware Configuration - DcRat config.
Config. Field
Value
Key (AES_256)

V3RnMHl2dllHRjVseGFEbTZQUVdhSm9Ib2dyMEl4WkU=

Ports

56595,6677

Hosts

127.0.0.1,center-mpeg.gl.at.ply.

Version

Install

false

Install-Folder

%AppData%

Install File

�

Mutex

弗שΕPkתi吉ΕGl迪Γץ7DvSΖ

Certificate

MIICKTCCAZKgAwIBAgIVAKDzlSNjJN+HkD60ACvOevgv6c5xMA0GCSqGSIb3DQEBDQUAMF0xDjAMBgNVBAMMBUVCT0xBMRMwEQYDVQQLDApxd3FkYW5jaHVuMRwwGgYDVQQKDBNEY1JhdCBCeSBxd3FkYW5jaHVuMQswCQYDVQQHDAJTSDELMAkGA1UEBhMCQ04wHhcNMjQxMDI3MDE0MDI0WhcNMzUwODA2MDE0MDI0WjAQMQ4wDAYDVQQDDAVEY1JhdDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAnNbWPTWgHgK8tadvgurWY6yksP2Lf+Z5DN7ATl5v1cVDfYH9D5kWBhXhjmHFc/MvoI01DLmL4x7g9gkl6uwDL0NJpS47uaRcNTAtoLLQzSL2/enwHDn2SfdjMsLIFFeRKyAicWM/cy1YsIA/UIBaBrGb7c+Fd9xJS2V2hroWeI0CAwEAAaMyMDAwHQYDVR0OBBYEFLHVij11NCmhsyxuKtByHiIQJyKsMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQENBQADgYEAgBOGuT5bLAqfkghzSrmEV3D/LzeotR3TXXfbd4lPY3V9s8RcLj+8ltcfYk7wXV5tj0xxuaMCGuYjrU8JBfVCFxWCp7h8M75mRvj7GqAoiaIO9sbOtf/qKPvnF7Ni4M3fbF1vGe2rvK4mKFjPLYiuBcUkxdZR9CyMyCDm

ServerSignature

fLuO5tShtui06Dvkul+3GwzraNnyWR7/v4T/bI0cWFGNc9MUZIUBr3xYenJDm4rGaGQ4BpSXLNnNTuQimii10P5KBRxKzBGCSIVuxF4IdzYglfeQiDnh78/X0krcjSwUwtW5/q/dJJmD7LtZCOzdQ6MNez/OD2nb

Anti-VM

null

PasteBin

false

BDOS

1

Delay

Default

Group

false

Artefacts
Name
Value Location
Key (AES_256)

V3RnMHl2dllHRjVseGFEbTZQUVdhSm9Ib2dyMEl4WkU=

Malicious

122dd982c56a9afb87a9c31e057ae39c

Ports

56595

Malicious

122dd982c56a9afb87a9c31e057ae39c

Ports

6677

Malicious

122dd982c56a9afb87a9c31e057ae39c

CnC

127.0.0.1

Malicious

122dd982c56a9afb87a9c31e057ae39c

CnC

center-mpeg.gl.at.ply.

Malicious

122dd982c56a9afb87a9c31e057ae39c

Mutex

弗שΕPkתi吉ΕGl迪Γץ7DvSΖ

Malicious

122dd982c56a9afb87a9c31e057ae39c

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙