Malicious
Malicious

29d87ed8ebc9b05426800ad3c13a8fcd

Share on LinkedIn
Print
PE Executable
MD5: 29d87ed8ebc9b05426800ad3c13a8fcd
Size: 56.32 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 29d87ed8ebc9b05426800ad3c13a8fcd
Sha1 96add574a522e59eadea6ee8355f74a43c46f742
Sha256 c92f2e4f8ebfa4a61f3b17663076cb8513f26bc60fbdbe6faea232f621b6e802
Sha384 000562c22cc244b56e8bc5e216bd7e80028b5c3f3f42c35fdbc5a82f87e168ffd50a6299e19a2ff3f8e4f7bf83e14d4f
Sha512 0ccbaf3997e5d34c304bfcbdcacfe459ed4f4607e6a982f30fb388d7ce28e9651f8556d4e9a3f70aa593575ef52f0c68b19208bfd48d13e73acd6d072877260a
SSDeep 1536:sqCUbsDnyNho6JypySDxwsNMDjXExI3pmhm:NCEsDn4o6I4SDxwsNMDjXExI3pm
TLSH 65431744BFEA4A05E2BD8F3468F655150634BA63E932EB1E4CD668DB13327C58C40FE6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] dllhuhuhuhu
cnc_host [H] 18.tcphuhuhuhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
Anti_CH Fhuhuhuhu
is_startup_folder [IsF] Fhuhuhuhu
USB_SP Fhuhuhuhu
is_user_reg [Isu] Fhuhuhuhu
cnc_port [P] 1huhuhuhu
reg_key [RG] 0caff8huhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] Vihuhuhuhu
version [VR] <- NjRhuhuhuhuhuhuhuhuhuhuhu
splitter [Y] Y262huhuhuhu
MSGE Dihuhuhuhu
MSGT Thhuhuhuhu
MSGB Sorry,huhuhuhuhuhuhuhuhuhuhu
MSGSYM vbChuhuhuhu
OBITO Dihuhuhuhu
TSKE Dihuhuhuhu
TSK Wirehuhuhuhuhuhuhu
KAKASHI Dihuhuhuhu
AKATSUKI Dihuhuhuhu
CLEANSWEEP Dihuhuhuhu
PASTEE Dihuhuhuhu
PASTEBIN https:huhuhuhuhuhuhuhuhuhuhu
CLIP nhuhuhuhu
UAC Dihuhuhuhu
nowifi ohuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
539
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
539
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
CnC CNCmalicious
18.tcphuhuhuhuhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙