Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5: 27e6a6b67007ffa73aa4efc766dcdfd9
Size: 77.82 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 27e6a6b67007ffa73aa4efc766dcdfd9
Sha1 de7bd2aebb658724f4ee4fcd4dbab627b786f28b
Sha256 b60e9d25fa67a6abff4209e4419b52250e447b986f8ad459113c874bc72f676c
Sha384 266b173fd5b0ab1e1d5d631184fcee2640935c829633b3056c1e702e6c0e49bea034ef92e6e931fcbb15f8324b3263bb
Sha512 66a4ae7f2add696623a3da2464d10d0c2e557aae312088229c41bd7a22ba059f18b8dcd00cf8d2b230156f59dd559a6dd37992ecd80a953a65849d47dd510a7f
SSDeep 1536:1dH0MJaSaVr5MDainKAGXDCaw+ovnBJC:7HHJa/Vr1inB3/+CnBJC
TLSH 8D733B18BBEBC526E1ED9A7589E113054335D3563603DB4F2CC8039A4F23BC79F4669A
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Client.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Config. Field Value
Key (AES_256) bTZIUEhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature Itu9Gkhuhuhuhuhuhuhuhuhuhuhu
Install fhuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install-Folder %Aphuhuhuhu
Version 0.huhuhuhu
Hosts ricardhuhuhuhuhuhuhuhuhuhuhu
Ports 5huhuhuhu
Mutex Asynchuhuhuhuhuhuhu
Delay 3huhuhuhu
Group ZChuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
SERVERZCUELLAR.exe
Full Name
SERVERZCUELLAR.exe
EntryPoint
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Scope Name
SERVERZCUELLAR.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
SERVERZCUELLAR
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
135
Main Method
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Main IL Instruction Count
3
Main IL
call System.Void hyBi4B7CHOZ0PcM2da.BrEOWILUFmZ9AtRTw7::lLHifFIsCLsZtjvFfN0i()
call System.Void Client.Program::Main()
ret <null>
Module Name
SERVERZCUELLAR.exe
Full Name
SERVERZCUELLAR.exe
EntryPoint
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Scope Name
SERVERZCUELLAR.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
SERVERZCUELLAR
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
135
Main Method
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Main IL Instruction Count
3
Main IL
call System.Void hyBi4B7CHOZ0PcM2da.BrEOWILUFmZ9AtRTw7::lLHifFIsCLsZtjvFfN0i()
call System.Void Client.Program::Main()
ret <null>
Key (AES_256) MUTEXmalicious
bTZIUEhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
ricardhuhuhuhuhuhuhuhuhuhuhu
Ports PORTmalicious
5huhuhuhu
Mutex MUTEXmalicious
Asynchuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙