Malicious
Malicious

13fe4fd84d2f0fe65fe209c4ee390752

Share on LinkedIn
Print
PE Executable
MD5: 13fe4fd84d2f0fe65fe209c4ee390752
Size: 32.26 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 13fe4fd84d2f0fe65fe209c4ee390752
Sha1 3bb02bfec1d2c0723baac811b7a2ed2a9eff3d2c
Sha256 895fea5f9576b02251d5c3b6d49e5d4611d4255789744d56599d5b5ede7dd563
Sha384 3c02bf07d3caddbe187804414b312d52f8e8b4c44cc9bbf80e4536b641728ef4b6b87900c25e20cd871369c476cee412
Sha512 7e4727eb2616933ead9c95269eb61fcba224d1514d269b9407456cca5ad26c0a64ea77bbb66e5ed00788c5dd329e4e64a50fa0def0a9ef14bde86bef3be6c5a7
SSDeep 768:UzUPYZxTDezxp+BG9a3AZ3vwdQmIDUu0tiRIj:vsahhkQVkTj
TLSH 91E21B6DFBF64466D2BD0AB50571950013B4E003E523F77E4ECB24A62B6B6D84B88DF2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] Windowhuhuhuhuhuhuhu
cnc_host [H] beebhuhuhuhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
Anti_CH Fhuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
USB_SP Thuhuhuhu
is_user_reg [Isu] Thuhuhuhu
cnc_port [P] 4huhuhuhu
reg_key [RG] 0e6033huhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] flyhuhuhuhu
version [VR] 0huhuhuhu
splitter [Y] Y262huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
241
Main Method
System.Void j.A::main()
Main IL Instruction Count
4
Main IL
nop <null>
call System.Void j.OK::ko()
nop <null>
ret <null>
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
241
Main Method
System.Void j.A::main()
Main IL Instruction Count
4
Main IL
nop <null>
call System.Void j.OK::ko()
nop <null>
ret <null>
CnC CNCmalicious
beebhuhuhuhuhuhuhu
Port PORTmalicious
4huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙