Malicious
Malicious

198adff053c489a0608a4952bb2608ce

PE Executable
MD5: 198adff053c489a0608a4952bb2608ce
Size: 56.32 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 198adff053c489a0608a4952bb2608ce
Sha1 e042f79fe324da3908b507d4510024c04c90bcb6
Sha256 bc8de4497ab08ddbc33aa7ce4a50b4550f132e9a6d893a953e2e3bbba3489ed8
Sha384 cc799d0c8f58cb2d29c1f785bc4e2741e412556128a4ba3af98716d0bad7f2682f046b15b43b1551b187b74e8973d38a
Sha512 4086dcdf443df18978649b133263b6869a6d36c78791c4e7e71379c16c2e4c7dc13d6f1f17a166e9b29999fba11c21f3b797c7935a4eade69da5e7d174e3ed0c
SSDeep 1536:E2ZMDnE4uNhty4X+SChDmwsNMDQnXExI3pm+m:pMDnlIk4XohDmwsNMDQnXExI3pm
TLSH 6B431744BFEA4A01E2BD8F3468F655150634AA63E532EB1F48D668DB17327C58C80FE6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] dllhuhuhuhu
cnc_host [H] 32.tchuhuhuhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
Anti_CH Thuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
USB_SP Fhuhuhuhu
is_user_reg [Isu] Thuhuhuhu
cnc_port [P] 1huhuhuhu
reg_key [RG] 3daf5dhuhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] Vihuhuhuhu
version [VR] <- NjRhuhuhuhuhuhuhuhuhuhuhu
splitter [Y] Y262huhuhuhu
MSGE Dihuhuhuhu
MSGT Thhuhuhuhu
MSGB Sorry,huhuhuhuhuhuhuhuhuhuhu
MSGSYM vbChuhuhuhu
OBITO Dihuhuhuhu
TSKE Dihuhuhuhu
TSK Wirehuhuhuhuhuhuhu
KAKASHI Dihuhuhuhu
AKATSUKI Dihuhuhuhu
CLEANSWEEP Dihuhuhuhu
PASTEE Dihuhuhuhu
PASTEBIN https:huhuhuhuhuhuhuhuhuhuhu
CLIP nhuhuhuhu
UAC Dihuhuhuhu
nowifi ohuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
539
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
539
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
CnC CNCmalicious
32.tchuhuhuhuhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] dllhuhuhuhu
cnc_host [H] 32.tchuhuhuhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
Anti_CH Thuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
USB_SP Fhuhuhuhu
is_user_reg [Isu] Thuhuhuhu
cnc_port [P] 1huhuhuhu
reg_key [RG] 3daf5dhuhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] Vihuhuhuhu
version [VR] <- NjRhuhuhuhuhuhuhuhuhuhuhu
splitter [Y] Y262huhuhuhu
MSGE Dihuhuhuhu
MSGT Thhuhuhuhu
MSGB Sorry,huhuhuhuhuhuhuhuhuhuhu
MSGSYM vbChuhuhuhu
OBITO Dihuhuhuhu
TSKE Dihuhuhuhu
TSK Wirehuhuhuhuhuhuhu
KAKASHI Dihuhuhuhu
AKATSUKI Dihuhuhuhu
CLEANSWEEP Dihuhuhuhu
PASTEE Dihuhuhuhu
PASTEBIN https:huhuhuhuhuhuhuhuhuhuhu
CLIP nhuhuhuhu
UAC Dihuhuhuhu
nowifi ohuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
32.tchuhuhuhuhuhuhu
198adff053c489a0608a4952bb2608ce
Port PORTmalicious
1huhuhuhu
198adff053c489a0608a4952bb2608ce
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙