Malicious
PE Executable
MD5: 16a2b7f149c3196299232a6d30d414aa
Size: 28.16 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 16a2b7f149c3196299232a6d30d414aa |
| Sha1 | 9ee6f8b5afcdef110f24835004979b899dee94ed |
| Sha256 | ebd9d6ef8b792ba88aa5edbd9bc093ec8739729fecc8507c8d3b158c02f09024 |
| Sha384 | 5d7b2fc428097a81de75b10f0b09bf8e5bcd4a792d7d46678f5a2fabe9c177614522b84f394d33961062747b427085a6 |
| Sha512 | ec7bec589feda6451003e9ffb1a61b4678ff00e2afdb736a6eca583e9de2485da5d742cdbb6e15039192e1532e422a687f2e1dd111a4d0f99b0c8708cc57e52f |
| SSDeep | 384:ATdv2D9YfxWceOsVa/KFHbxFH9qbuUsDbQxnCJfJBndnjJ3KxB+:edvhi1VDHVFIbdBiBnOxB+ |
| TLSH | E5C22C0873E8C572D2FE4ABA883385009775D55B9913D76A6FC890AE2E237CD8B14FD4 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
| Config. Field | Value |
|---|---|
| Key (AES_256) | Byhuhuhuhu |
| Pastebin | -huhuhuhu |
| Install | fhuhuhuhu |
| Install File | Tehuhuhuhu |
| Install-Folder | %huhuhuhu |
| Version | 0.huhuhuhu |
| Hosts | cm8huhuhuhu |
| Ports | 4huhuhuhu |
| Mutex | Aphuhuhuhu |
| Delay | 0huhuhuhu |
| Group | NYhuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Module Name | CM88APP.exe |
| Full Name | CM88APP.exe |
| EntryPoint | System.Void Client.Program::Main() |
| Scope Name | CM88APP.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | CM88APP |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 122 |
| Main Method | System.Void Client.Program::Main() |
| Main IL Instruction Count | 101 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Info | |
Key (AES_256)
MUTEXmalicious
Byhuhuhuhu
CnC
CNCmalicious
cm8huhuhuhu
Ports
PORTmalicious
4huhuhuhu
Mutex
MUTEXmalicious
Aphuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential