Malicious
Malicious

161cffce699888fd263578084a863522

Share on LinkedIn
Print
PE Executable
MD5: 161cffce699888fd263578084a863522
Size: 40.45 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 161cffce699888fd263578084a863522
Sha1 0c7e79e2d0ebf1b02997e9ce98c5fc9605b3d669
Sha256 c48688e58baebab464a87519cc98b0184f1368977429891f3b3b08ce4afa5eea
Sha384 8ad49701813454fb281f2256e7c07c55738194d1e0f2cd6379f1a9e70e5eecc1ed2baebb9d9cd22387c07efa06a9cd80
Sha512 e2c64f2e5629290fafa6b25359d3871509a59a76d6e0eb831bb06c30e6aaab95a09399efdeeceb8bc069e222a166ae8e719f093ded530786714518e0d1aac90e
SSDeep 768:ddxLdpot/l2huErHV2F3F9UXO+hzIAfO:ddxZatSu+HkF19UXO+pl2
TLSH 66034A08B7904615DAFE6FF55AF3B1020B35F2135907DB5E08D58A9F6B27B808A027E6
PeID
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Mutex F6pWUhuhuhuhuhuhuhu
Hosts 207.huhuhuhuhuhuhu
Port 7huhuhuhu
KEY <V74PVhuhuhuhuhuhuhu
USBNM <Xwhuhuhuhu
family xhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
XWormClient1.exe
Full Name
XWormClient1.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
XWormClient1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XWormClient1
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
206
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
84
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::Hosts
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Hosts
ldsfld System.String Settings::Port
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Port
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
ldsfld System.String Settings::BTC
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::BTC
ldsfld System.String Settings::ETH
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::ETH
ldsfld System.String Settings::TRC
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::TRC
leave.s IL_00DA: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_00DA: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00E7: call System.Void Stub.Helper::PreventSleep()
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
call System.String Stub.ClientSocket::UAC()
call System.Boolean Microsoft.VisualBasic.CompilerServices.Conversions::ToBoolean(System.String)
brfalse.s IL_0129: ldnull
call System.Void Stub.ProcessCritical::CriticalProcess_Enable()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__3()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.0 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__4()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldloc.0 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Module Name
XWormClient1.exe
Full Name
XWormClient1.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
XWormClient1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XWormClient1
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
206
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
84
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::Hosts
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Hosts
ldsfld System.String Settings::Port
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Port
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
ldsfld System.String Settings::BTC
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::BTC
ldsfld System.String Settings::ETH
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::ETH
ldsfld System.String Settings::TRC
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::TRC
leave.s IL_00DA: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_00DA: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00E7: call System.Void Stub.Helper::PreventSleep()
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
call System.String Stub.ClientSocket::UAC()
call System.Boolean Microsoft.VisualBasic.CompilerServices.Conversions::ToBoolean(System.String)
brfalse.s IL_0129: ldnull
call System.Void Stub.ProcessCritical::CriticalProcess_Enable()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__3()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.0 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__4()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldloc.0 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Mutex MUTEXmalicious
F6pWUhuhuhuhuhuhuhu
CnC CNCmalicious
207.huhuhuhuhuhuhu
Port PORTmalicious
7huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙