Malicious
Malicious

284ad6b6c0c24e56c56b681f4492a1e3

Share on LinkedIn
Print
PE Executable
MD5: 284ad6b6c0c24e56c56b681f4492a1e3
Size: 33.79 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 284ad6b6c0c24e56c56b681f4492a1e3
Sha1 34d8054a787dea343e82e3794d8e1c95bbf66190
Sha256 d7d42055585aaf602b8a00d8d62afe4150da70b6063d6b1e671cd39845d0b5ab
Sha384 5431597d699be25e6b155f047e79a8e6d2d957d91e42007b7cf60503046510f2d48d477d6b80a76082271676623e33c4
Sha512 265cbe45511d9dad8aece528652986c6f43c2ef69564e08d27966640ebc9eea88ae72550848a8dcf8117940b98c8f8dedd0c9f933a90d048d0b1af0128af6f5b
SSDeep 384:f8aZYC9twBNdcvFaly2H0dbJo6HghcASEJqc/ZmRvR6JZlbw8hqIusZzZpKTyFL1:TY+sNKqNHnSdRpcnurTyFR
TLSH 66E2F94A7EA58851C87C06B08B7596D403B0E187C41EDF2B8CC561DB6BF3AF91D48AF9
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0032
ID:0
RT_GROUP_CURSOR4
ID:0032
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
victim_name [VN] Hahuhuhuhu
version [VR] 0huhuhuhu
executable_name [EXE] serhuhuhuhu
directory [DR] Thuhuhuhu
reg_key [RG] 81a05ahuhuhuhuhuhuhuhuhuhuhu
cnc_host [H] joaoshuhuhuhuhuhuhu
cnc_port [P] 1huhuhuhu
splitter [Y] |huhuhuhu
BD [BD] Fhuhuhuhu
is_dir_defined [Idr] Thuhuhuhu
is_startup_folder [IsF] Fhuhuhuhu
is_user_reg [Isu] Thuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
packet_size [b] 5huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
j.exe
Full Name
j.exe
EntryPoint
System.Void j.A::main()
Scope Name
j.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
j
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Info
PE Detect: PeReader OK (file layout)
Total Strings
214
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
Module Name
j.exe
Full Name
j.exe
EntryPoint
System.Void j.A::main()
Scope Name
j.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
j
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
214
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
CnC CNCmalicious
joaoshuhuhuhuhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙