Malicious
PE Executable
MD5: 161cffce699888fd263578084a863522
Size: 40.45 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 161cffce699888fd263578084a863522 |
| Sha1 | 0c7e79e2d0ebf1b02997e9ce98c5fc9605b3d669 |
| Sha256 | c48688e58baebab464a87519cc98b0184f1368977429891f3b3b08ce4afa5eea |
| Sha384 | 8ad49701813454fb281f2256e7c07c55738194d1e0f2cd6379f1a9e70e5eecc1ed2baebb9d9cd22387c07efa06a9cd80 |
| Sha512 | e2c64f2e5629290fafa6b25359d3871509a59a76d6e0eb831bb06c30e6aaab95a09399efdeeceb8bc069e222a166ae8e719f093ded530786714518e0d1aac90e |
| SSDeep | 768:ddxLdpot/l2huErHV2F3F9UXO+hzIAfO:ddxZatSu+HkF19UXO+pl2 |
| TLSH | 66034A08B7904615DAFE6FF55AF3B1020B35F2135907DB5E08D58A9F6B27B808A027E6 |
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
| Config. Field | Value |
|---|---|
| Mutex | F6pWUhuhuhuhuhuhuhu |
| Hosts | 207.huhuhuhuhuhuhu |
| Port | 7huhuhuhu |
| KEY | <V74PVhuhuhuhuhuhuhu |
| USBNM | <Xwhuhuhuhu |
| family | xhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | XWormClient1.exe |
| Full Name | XWormClient1.exe |
| EntryPoint | System.Void Stub.Main::Main() |
| Scope Name | XWormClient1.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | XWormClient1 |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 206 |
| Main Method | System.Void Stub.Main::Main() |
| Main IL Instruction Count | 84 |
| Main IL | |
| Module Name | XWormClient1.exe |
| Full Name | XWormClient1.exe |
| EntryPoint | System.Void Stub.Main::Main() |
| Scope Name | XWormClient1.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | XWormClient1 |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 206 |
| Main Method | System.Void Stub.Main::Main() |
| Main IL Instruction Count | 84 |
| Main IL | |
Mutex
MUTEXmalicious
F6pWUhuhuhuhuhuhuhu
CnC
CNCmalicious
207.huhuhuhuhuhuhu
Port
PORTmalicious
7huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential