Malicious
Malicious

2ac1f830806ce3bdd35cdcb957f139ba

Share on LinkedIn
Print
PE Executable
MD5: 2ac1f830806ce3bdd35cdcb957f139ba
Size: 356.35 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 2ac1f830806ce3bdd35cdcb957f139ba
Sha1 00f6a68fef995c15c116c48b18d9611db036c1e5
Sha256 9270d36aa57eec3d44dc2d66929551198cb8a31d0ef383a726c38b75ad8144ba
Sha384 5f1afa68bc650399116d6b3ae215c93b3a389244ad3cc5796e0c388f74c7b8b556b4e3aec54e1286ac307621162cd6b3
Sha512 5eca9c6f9be362f4ca7a7c5e7b5e8e9c8ba1b46558575b2703de982dbcc2a61b1cf5e7af3c292e4cb745994dcd1198cf0dd50648f1dcd5f82aefc310e49b061d
SSDeep 6144:kzNHXf500MbHkuNarU5bX1z0oaGMHAM2S06:ud509kuNAUl1zEGMHAI06
TLSH E1747C1373A8D67BD1BE173BE53206056BB0D407B712E38B5A6855BCAC123868D91BF3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
3 / 3
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key a8O1Ybhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port 1huhuhuhu
Host 91.1huhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory Suhuhuhuhu
InstallName Clihuhuhuhu
Install 0huhuhuhu
Startup 0huhuhuhu
Mutex QSR_MUhuhuhuhuhuhuhuhuhuhuhu
StartupKey Quasarhuhuhuhuhuhuhu
HideFile 0huhuhuhu
EnableLogger 0huhuhuhu
Tag Ofhuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::觤궄뢎舯ꆈ陂ﻗ誂邥짶㠢边⃠敡췐엙싌쉱꽟(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean 喁⴫놰귺顉�얼赤풾踂䳡薟즇껀눳픠颢::籩㞠쑁犄⮴帍⎎鸏삐堂뙸Ⰼ쳔⬖䱆痙㶜붫ⷼ()
brfalse.s IL_0040: call System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::‾뚨⮶俗娯耄㻜쬉⻯烢㡊ﳯ鸉勶䜠g()
call System.Boolean 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::꒞丙㲧퐰徘⢰ⓖ詉쏤뮞呾簡�伪潯졷鼏ᷖ()
brfalse.s IL_0040: call System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::‾뚨⮶俗娯耄㻜쬉⻯烢㡊ﳯ鸉勶䜠g()
call System.Boolean ⭙໱軽靊ሹꔼ죽糯㊫㿶ᑔ汲愭㳄辒�Ჾ횪::get_Exiting()
brtrue.s IL_0040: call System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::‾뚨⮶俗娯耄㻜쬉⻯烢㡊ﳯ鸉勶䜠g()
ldsfld ⭙໱軽靊ሹꔼ죽糯㊫㿶ᑔ汲愭㳄辒�Ჾ횪 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::題뎔ទਸৢ뤒ঁ띌࿧䬇漽띏嶁㝒둱䁄검
callvirt System.Void ⭙໱軽靊ሹꔼ죽糯㊫㿶ᑔ汲愭㳄辒�Ჾ횪::쾹l鶫䎀䒟会Ɇ᧭绂쬞삘ℰ㯆季勒멐煅ꇎDZ()
call System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::‾뚨⮶俗娯耄㻜쬉⻯烢㡊ﳯ鸉勶䜠g()
call System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::ﱈᙼ왖迧ؗ㈌뤤ꦬ﷝쒷뭩岵ꁛ뮔鬶䎌찲()
ret <null>
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::觤궄뢎舯ꆈ陂ﻗ誂邥짶㠢边⃠敡췐엙싌쉱꽟(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean 喁⴫놰귺顉�얼赤풾踂䳡薟즇껀눳픠颢::籩㞠쑁犄⮴帍⎎鸏삐堂뙸Ⰼ쳔⬖䱆痙㶜붫ⷼ()
brfalse.s IL_0040: call System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::‾뚨⮶俗娯耄㻜쬉⻯烢㡊ﳯ鸉勶䜠g()
call System.Boolean 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::꒞丙㲧퐰徘⢰ⓖ詉쏤뮞呾簡�伪潯졷鼏ᷖ()
brfalse.s IL_0040: call System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::‾뚨⮶俗娯耄㻜쬉⻯烢㡊ﳯ鸉勶䜠g()
call System.Boolean ⭙໱軽靊ሹꔼ죽糯㊫㿶ᑔ汲愭㳄辒�Ჾ횪::get_Exiting()
brtrue.s IL_0040: call System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::‾뚨⮶俗娯耄㻜쬉⻯烢㡊ﳯ鸉勶䜠g()
ldsfld ⭙໱軽靊ሹꔼ죽糯㊫㿶ᑔ汲愭㳄辒�Ჾ횪 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::題뎔ទਸৢ뤒ঁ띌࿧䬇漽띏嶁㝒둱䁄검
callvirt System.Void ⭙໱軽靊ሹꔼ죽糯㊫㿶ᑔ汲愭㳄辒�Ჾ횪::쾹l鶫䎀䒟会Ɇ᧭绂쬞삘ℰ㯆季勒멐煅ꇎDZ()
call System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::‾뚨⮶俗娯耄㻜쬉⻯烢㡊ﳯ鸉勶䜠g()
call System.Void 簾뾒㒹뀒뙏⩍綴ਓ闏튔亷麢脄㋺᫬뻥䓻::ﱈᙼ왖迧ؗ㈌뤤ꦬ﷝쒷뭩岵ꁛ뮔鬶䎌찲()
ret <null>
CnC CNCmalicious
91.1huhuhuhuhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙