Malicious
Malicious

1ff95900cce08694505425ff7dd51ad4

PE Executable
MD5: 1ff95900cce08694505425ff7dd51ad4
Size: 48.64 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 1ff95900cce08694505425ff7dd51ad4
Sha1 bd21398e2d5db25b17b61eefbddef1efe81329c7
Sha256 5854b1c0839d6388d6d006338303337dd1de5001dcdff10dd13080a17b71fb87
Sha384 7fbb73728213da0cedda52e052a60264154c36b1a18aa9748da940491eed85342d178e4c0eadd5c8e9650d9d8f88835c
Sha512 7784be22cb3d7465d6b0bc3cc8155a8b156ed56270161284ce2cf7ac9c03468e9c43a8fe3d0399c75b0cde55f6e005675eb0d39a7ac5fbc9f2df133baad57c5c
SSDeep 768:AuYHKTsufqG9vSLjWUvlPRmo2qbMthx4sNzizZ/DPIPfQkMz0bt+M9Fa7aKlkNWc:AuYHKTsjMvSX2VddNw/MPfLRbt+MPa96
TLSH 27233C043BE9C166F2BE4F7858F32245867AF2673603D54E2CC4429B5A23FC59A426FD
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) N0Ftemhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature WvG3uwhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS thuhuhuhu
Anti-VM thuhuhuhu
Install File Chromhuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts forshuhuhuhu
Ports 4huhuhuhu
Mutex SlSChuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group forshuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
cXfyhZquZLR
Full Name
cXfyhZquZLR
EntryPoint
System.Void oNJMTCUshwqcigG.boZDaLmGCINY::Main()
Scope Name
cXfyhZquZLR
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
svchost
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Info
PE Detect: PeReader OK (file layout)
Main Method
System.Void oNJMTCUshwqcigG.boZDaLmGCINY::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::ugFFGtSwYMyaW
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean oNJMTCUshwqcigG.KAqgDmkdBjJF::TZsaegnhyINst()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean iDuMqCsoLlgok.yGdIhOElCdKn::ytyeexaBUSGv()
brtrue IL_0043: ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::ftklXWxEYKHit
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::ftklXWxEYKHit
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::IfVGXyqdNhJBkkfyI
call System.Void iDuMqCsoLlgok.hTYePTPfUAm::gDOBDvVNIYgTs()
ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::IfVGXyqdNhJBkkfyI
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::iyLlApqNyLPmoS
call System.Void zwjhiOMvHefEwV.otjovTswaSpMK::jnSySuvvjXw()
ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::iyLlApqNyLPmoS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void iDuMqCsoLlgok.FOWMKrltjdaAfi::CdrskamjTMU()
call System.Boolean iDuMqCsoLlgok.FOWMKrltjdaAfi::fhvoAhLqTamIIhs()
brfalse IL_0089: call System.Void iDuMqCsoLlgok.FOWMKrltjdaAfi::CdrskamjTMU()
call System.Void iDuMqCsoLlgok.AFvvcHaHZFF::PhWQdGhuhjYVyIu()
call System.Void iDuMqCsoLlgok.FOWMKrltjdaAfi::CdrskamjTMU()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean MqCqOfZvvEDO.AuKCuKLXmHosMh::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void MqCqOfZvvEDO.AuKCuKLXmHosMh::ZPelrEajcdCpkI()
call System.Void MqCqOfZvvEDO.AuKCuKLXmHosMh::MWQauvuNlc()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Module Name
cXfyhZquZLR
Full Name
cXfyhZquZLR
EntryPoint
System.Void oNJMTCUshwqcigG.boZDaLmGCINY::Main()
Scope Name
cXfyhZquZLR
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
svchost
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void oNJMTCUshwqcigG.boZDaLmGCINY::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::ugFFGtSwYMyaW
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean oNJMTCUshwqcigG.KAqgDmkdBjJF::TZsaegnhyINst()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean iDuMqCsoLlgok.yGdIhOElCdKn::ytyeexaBUSGv()
brtrue IL_0043: ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::ftklXWxEYKHit
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::ftklXWxEYKHit
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::IfVGXyqdNhJBkkfyI
call System.Void iDuMqCsoLlgok.hTYePTPfUAm::gDOBDvVNIYgTs()
ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::IfVGXyqdNhJBkkfyI
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::iyLlApqNyLPmoS
call System.Void zwjhiOMvHefEwV.otjovTswaSpMK::jnSySuvvjXw()
ldsfld System.String oNJMTCUshwqcigG.KAqgDmkdBjJF::iyLlApqNyLPmoS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void iDuMqCsoLlgok.FOWMKrltjdaAfi::CdrskamjTMU()
call System.Boolean iDuMqCsoLlgok.FOWMKrltjdaAfi::fhvoAhLqTamIIhs()
brfalse IL_0089: call System.Void iDuMqCsoLlgok.FOWMKrltjdaAfi::CdrskamjTMU()
call System.Void iDuMqCsoLlgok.AFvvcHaHZFF::PhWQdGhuhjYVyIu()
call System.Void iDuMqCsoLlgok.FOWMKrltjdaAfi::CdrskamjTMU()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean MqCqOfZvvEDO.AuKCuKLXmHosMh::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void MqCqOfZvvEDO.AuKCuKLXmHosMh::ZPelrEajcdCpkI()
call System.Void MqCqOfZvvEDO.AuKCuKLXmHosMh::MWQauvuNlc()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Key (AES_256) MUTEXmalicious
N0Ftemhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
forshuhuhuhu
Ports PORTmalicious
4huhuhuhu
Mutex MUTEXmalicious
SlSChuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Key (AES_256) N0Ftemhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature WvG3uwhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS thuhuhuhu
Anti-VM thuhuhuhu
Install File Chromhuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts forshuhuhuhu
Ports 4huhuhuhu
Mutex SlSChuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group forshuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Key (AES_256) MUTEXmalicious
N0Ftemhuhuhuhuhuhuhuhuhuhuhu
1ff95900cce08694505425ff7dd51ad4
CnC CNCmalicious
forshuhuhuhu
1ff95900cce08694505425ff7dd51ad4
Ports PORTmalicious
4huhuhuhu
1ff95900cce08694505425ff7dd51ad4
Mutex MUTEXmalicious
SlSChuhuhuhu
1ff95900cce08694505425ff7dd51ad4
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙