Malicious
Malicious

2bfbeaa25be3ec5055a3a53473bebc99

PE Executable
MD5: 2bfbeaa25be3ec5055a3a53473bebc99
Size: 49.15 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 2bfbeaa25be3ec5055a3a53473bebc99
Sha1 e12fe772e8c8f715e64c34addae2f930c2987ad5
Sha256 69cd34ef2d9b26fad86387d6ef3556a7a7bdd13bf7e45f810fd7c2bbff30974b
Sha384 83f889d280f9dcacc6a9a60d6bd94b26d3de336ad7826260ea1b6fca78affa41f909cd90ad85397a7a9958ba00906e5e
Sha512 e684673620e930d84d9b229f282491a5880315c29bc7cee0fb3a016a1987c8282f76f2503111959a6797b4fa5809667035970a8af938da2bea35e8e301f4f156
SSDeep 768:czXpEHBoMBHbzS/fPX3SpkPEA590TRXZ66QDY/X9u0hcbKyU:65EHBoMBHbzSPSpkPETKY/Xg8cbKy
TLSH 8F232B4973D59521C5FD9E385565A20207BAB20BAC1FFB0D0CDADCE91BB37D10D10AEA
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
cnc_host [st] 209.huhuhuhuhuhuhu
cnc_port [PT] 2huhuhuhu
ml Fhuhuhuhu
hid %huhuhuhu
UAC Fhuhuhuhu
NE Syhuhuhuhu
Trs WWW.huhuhuhuhuhuhu
Dow 55huhuhuhu
Bt3 2huhuhuhu
Bt4 %huhuhuhu
TipoDeIconesMensagem Quhuhuhuhu
TipoDeButaoMensagem Aborthuhuhuhuhuhuhu
TituleMensagem Ehuhuhuhu
TxtMensagem Systehuhuhuhuhuhuhu
OutreMensagems %Outrhuhuhuhuhuhuhu
packet_size [b] 5huhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] svchuhuhuhu
Cc Syhuhuhuhu
Cz Syhuhuhuhu
Ts 5huhuhuhu
M $huhuhuhu
BR $huhuhuhu
is_dir_defined [Idr] Thuhuhuhu
is_startup_folder [IsF] Fhuhuhuhu
is_user_reg [Isu] Thuhuhuhu
Cs Fhuhuhuhu
Hi Thuhuhuhu
Sle Fhuhuhuhu
Ant Fhuhuhuhu
Tss Fhuhuhuhu
Us Thuhuhuhu
csh Fhuhuhuhu
Ln Fhuhuhuhu
JS Fhuhuhuhu
VB Fhuhuhuhu
shh Fhuhuhuhu
Msg Fhuhuhuhu
Prs Fhuhuhuhu
Trr Fhuhuhuhu
Bc3 Fhuhuhuhu
cnc_host [HH] Thuhuhuhu
KLG Fhuhuhuhu
reg_key [RG] Syhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] Hahuhuhuhu
splitter [Y] Lohuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void OK::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
503
Main Method
System.Void OK::main()
Main IL Instruction Count
37
Main IL
ldsfld System.Boolean OK::HH
brfalse.s IL_0086: call System.Void OK::ko()
ldsfld System.IO.FileInfo OK::LO
callvirt System.String System.IO.FileSystemInfo::get_FullName()
call System.Object OK::HHK(System.String)
pop <null>
call My.MyComputer My.MyProject::get_Computer()
callvirt Microsoft.VisualBasic.MyServices.RegistryProxy Microsoft.VisualBasic.Devices.ServerComputer::get_Registry()
callvirt Microsoft.Win32.RegistryKey Microsoft.VisualBasic.MyServices.RegistryProxy::get_LocalMachine()
ldsfld System.String OK::sf
ldc.i4.1 <null>
callvirt Microsoft.Win32.RegistryKey Microsoft.Win32.RegistryKey::OpenSubKey(System.String,System.Boolean)
ldsfld System.String OK::RG
ldsfld System.String OK::a
callvirt System.Void Microsoft.Win32.RegistryKey::SetValue(System.String,System.Object)
ldsfld Microsoft.VisualBasic.Devices.Computer OK::F
callvirt Microsoft.VisualBasic.MyServices.RegistryProxy Microsoft.VisualBasic.Devices.ServerComputer::get_Registry()
callvirt Microsoft.Win32.RegistryKey Microsoft.VisualBasic.MyServices.RegistryProxy::get_LocalMachine()
ldsfld System.String OK::sf
ldc.i4.1 <null>
callvirt Microsoft.Win32.RegistryKey Microsoft.Win32.RegistryKey::OpenSubKey(System.String,System.Boolean)
ldsfld System.String OK::RG
ldsfld System.String OK::a
callvirt System.Void Microsoft.Win32.RegistryKey::SetValue(System.String,System.Object)
leave.s IL_0086: call System.Void OK::ko()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.0 <null>
ldloc.0 <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
ldloc.0 <null>
stloc.1 <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0086: call System.Void OK::ko()
call System.Void OK::ko()
ret <null>
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void OK::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
503
Main Method
System.Void OK::main()
Main IL Instruction Count
37
Main IL
ldsfld System.Boolean OK::HH
brfalse.s IL_0086: call System.Void OK::ko()
ldsfld System.IO.FileInfo OK::LO
callvirt System.String System.IO.FileSystemInfo::get_FullName()
call System.Object OK::HHK(System.String)
pop <null>
call My.MyComputer My.MyProject::get_Computer()
callvirt Microsoft.VisualBasic.MyServices.RegistryProxy Microsoft.VisualBasic.Devices.ServerComputer::get_Registry()
callvirt Microsoft.Win32.RegistryKey Microsoft.VisualBasic.MyServices.RegistryProxy::get_LocalMachine()
ldsfld System.String OK::sf
ldc.i4.1 <null>
callvirt Microsoft.Win32.RegistryKey Microsoft.Win32.RegistryKey::OpenSubKey(System.String,System.Boolean)
ldsfld System.String OK::RG
ldsfld System.String OK::a
callvirt System.Void Microsoft.Win32.RegistryKey::SetValue(System.String,System.Object)
ldsfld Microsoft.VisualBasic.Devices.Computer OK::F
callvirt Microsoft.VisualBasic.MyServices.RegistryProxy Microsoft.VisualBasic.Devices.ServerComputer::get_Registry()
callvirt Microsoft.Win32.RegistryKey Microsoft.VisualBasic.MyServices.RegistryProxy::get_LocalMachine()
ldsfld System.String OK::sf
ldc.i4.1 <null>
callvirt Microsoft.Win32.RegistryKey Microsoft.Win32.RegistryKey::OpenSubKey(System.String,System.Boolean)
ldsfld System.String OK::RG
ldsfld System.String OK::a
callvirt System.Void Microsoft.Win32.RegistryKey::SetValue(System.String,System.Object)
leave.s IL_0086: call System.Void OK::ko()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.0 <null>
ldloc.0 <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
ldloc.0 <null>
stloc.1 <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_0086: call System.Void OK::ko()
call System.Void OK::ko()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
cnc_host [st] 209.huhuhuhuhuhuhu
cnc_port [PT] 2huhuhuhu
ml Fhuhuhuhu
hid %huhuhuhu
UAC Fhuhuhuhu
NE Syhuhuhuhu
Trs WWW.huhuhuhuhuhuhu
Dow 55huhuhuhu
Bt3 2huhuhuhu
Bt4 %huhuhuhu
TipoDeIconesMensagem Quhuhuhuhu
TipoDeButaoMensagem Aborthuhuhuhuhuhuhu
TituleMensagem Ehuhuhuhu
TxtMensagem Systehuhuhuhuhuhuhu
OutreMensagems %Outrhuhuhuhuhuhuhu
packet_size [b] 5huhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] svchuhuhuhu
Cc Syhuhuhuhu
Cz Syhuhuhuhu
Ts 5huhuhuhu
M $huhuhuhu
BR $huhuhuhu
is_dir_defined [Idr] Thuhuhuhu
is_startup_folder [IsF] Fhuhuhuhu
is_user_reg [Isu] Thuhuhuhu
Cs Fhuhuhuhu
Hi Thuhuhuhu
Sle Fhuhuhuhu
Ant Fhuhuhuhu
Tss Fhuhuhuhu
Us Thuhuhuhu
csh Fhuhuhuhu
Ln Fhuhuhuhu
JS Fhuhuhuhu
VB Fhuhuhuhu
shh Fhuhuhuhu
Msg Fhuhuhuhu
Prs Fhuhuhuhu
Trr Fhuhuhuhu
Bc3 Fhuhuhuhu
cnc_host [HH] Thuhuhuhu
KLG Fhuhuhuhu
reg_key [RG] Syhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] Hahuhuhuhu
splitter [Y] Lohuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙