Malicious
Malicious

1e7f18f1e50a222a17888d3de9e63730

Share on LinkedIn
Print
PE Executable
MD5: 1e7f18f1e50a222a17888d3de9e63730
Size: 44.03 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 1e7f18f1e50a222a17888d3de9e63730
Sha1 1159f0e2879c2d70dadc31bcc3356d62c69cb264
Sha256 c767bb6b6dd0b149e46b7066269b6d9fac1f9eb2dcafcec59475fd78a8af7861
Sha384 965fbc77c2fc514ef0ab223b5413e2cfd54af4102a3f560cc7e1dfcb21b24aea72721b3c4cdae8eb19562bc335dbc1e6
Sha512 a728ccf3e6a1c4a2a9ac0545bf1e6ffd595d5208fa2e43ae66917aa0a1c01148a1bf356ca05aeb2142ee3fec53e8de6747bbf99af8834497d573b04c0e1d7035
SSDeep 384:kZylX7xdW/IUyNZa55EFiTYM0EvbV56lpzYIij+ZsNO3PlpJKkkjh/TzF7pWn+/l:SorxIghNZk5EFiTVTbCpuXQ/o33+L
TLSH 0513D78DB694E174D5FF8BF1B4A2B2890B71A017A902D30F99F114D94BB3AC09611EE7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Stub.Resources.resources
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] Dllhuhuhuhu
icn #huhuhuhu
is_dir_defined [Idr] Thuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
RegistrySt Thuhuhuhu
xDlol1 Javhuhuhuhu
Sleep Fhuhuhuhu
Sleep1 1huhuhuhu
reg_key [RG] Windhuhuhuhuhuhuhu
task [Task] Thuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
Hide Thuhuhuhu
HP Thuhuhuhu
SPR fhuhuhuhu
victim_name [VN] Hahuhuhuhu
version [VR] Njrat huhuhuhuhuhuhuhuhuhuhu
splitter [Y] |Hhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void Stub.OK.j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
436
Main Method
System.Void Stub.OK.j.A::main()
Main IL Instruction Count
20
Main IL
ldc.i4.1 <null>
stsfld System.Boolean Stub.OK.j.A::runx
ldnull <null>
ldftn System.Void Stub.OK.j.A::timx_run()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stsfld System.Threading.Thread Stub.OK.j.A::thx
ldsfld System.Threading.Thread Stub.OK.j.A::thx
callvirt System.Void System.Threading.Thread::Start()
ldc.i4.1 <null>
stsfld System.Boolean Stub.OK.j.A::runy
ldnull <null>
ldftn System.Void Stub.OK.j.A::timy_run()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stsfld System.Threading.Thread Stub.OK.j.A::thy
ldsfld System.Threading.Thread Stub.OK.j.A::thy
callvirt System.Void System.Threading.Thread::Start()
call System.Void Stub.OK.j.OK::ko()
ret <null>
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void Stub.OK.j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
436
Main Method
System.Void Stub.OK.j.A::main()
Main IL Instruction Count
20
Main IL
ldc.i4.1 <null>
stsfld System.Boolean Stub.OK.j.A::runx
ldnull <null>
ldftn System.Void Stub.OK.j.A::timx_run()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stsfld System.Threading.Thread Stub.OK.j.A::thx
ldsfld System.Threading.Thread Stub.OK.j.A::thx
callvirt System.Void System.Threading.Thread::Start()
ldc.i4.1 <null>
stsfld System.Boolean Stub.OK.j.A::runy
ldnull <null>
ldftn System.Void Stub.OK.j.A::timy_run()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stsfld System.Threading.Thread Stub.OK.j.A::thy
ldsfld System.Threading.Thread Stub.OK.j.A::thy
callvirt System.Void System.Threading.Thread::Start()
call System.Void Stub.OK.j.OK::ko()
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙