Malicious
Malicious

2bfbeaa25be3ec5055a3a53473bebc99

Share on LinkedIn
Print
PE Executable
MD5: 2bfbeaa25be3ec5055a3a53473bebc99
Size: 49.15 KB
application/x-dosexec
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Low

Hash
Hash Value
MD5
2bfbeaa25be3ec5055a3a53473bebc99
Sha1
e12fe772e8c8f715e64c34addae2f930c2987ad5
Sha256
69cd34ef2d9b26fad86387d6ef3556a7a7bdd13bf7e45f810fd7c2bbff30974b
Sha384
83f889d280f9dcacc6a9a60d6bd94b26d3de336ad7826260ea1b6fca78affa41f909cd90ad85397a7a9958ba00906e5e
Sha512
e684673620e930d84d9b229f282491a5880315c29bc7cee0fb3a016a1987c8282f76f2503111959a6797b4fa5809667035970a8af938da2bea35e8e301f4f156
SSDeep
768:czXpEHBoMBHbzS/fPX3SpkPEA590TRXZ66QDY/X9u0hcbKyU:65EHBoMBHbzSPSpkPETKY/Xg8cbKy
TLSH
8F232B4973D59521C5FD9E385565A20207BAB20BAC1FFB0D0CDADCE91BB37D10D10AEA

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
Malware Configuration - njRAT config.
Config. Field
Value
cnc_host [st]
209.huhuhuhuhuhuhu
cnc_port [PT]
2huhuhuhu
ml
Fhuhuhuhu
hid
%huhuhuhu
UAC
Fhuhuhuhu
NE
Syhuhuhuhu
Trs
WWW.huhuhuhuhuhuhu
Dow
55huhuhuhu
Bt3
2huhuhuhu
Bt4
%huhuhuhu
TipoDeIconesMensagem
Quhuhuhuhu
TipoDeButaoMensagem
Aborthuhuhuhuhuhuhu
TituleMensagem
Ehuhuhuhu
TxtMensagem
Systehuhuhuhuhuhuhu
OutreMensagems
%Outrhuhuhuhuhuhuhu
packet_size [b]
5huhuhuhu
directory [DR]
Thuhuhuhu
executable_name [EXE]
svchuhuhuhu
Cc
Syhuhuhuhu
Cz
Syhuhuhuhu
Ts
5huhuhuhu
M
$huhuhuhu
BR
$huhuhuhu
is_dir_defined [Idr]
Thuhuhuhu
is_startup_folder [IsF]
Fhuhuhuhu
is_user_reg [Isu]
Thuhuhuhu
Cs
Fhuhuhuhu
Hi
Thuhuhuhu
Sle
Fhuhuhuhu
Ant
Fhuhuhuhu
Tss
Fhuhuhuhu
Us
Thuhuhuhu
csh
Fhuhuhuhu
Ln
Fhuhuhuhu
JS
Fhuhuhuhu
VB
Fhuhuhuhu
shh
Fhuhuhuhu
Msg
Fhuhuhuhu
Prs
Fhuhuhuhu
Trr
Fhuhuhuhu
Bc3
Fhuhuhuhu
cnc_host [HH]
Thuhuhuhu
KLG
Fhuhuhuhu
reg_key [RG]
Syhuhuhuhu
reg_path [sf]
Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN]
Hahuhuhuhu
splitter [Y]
Lohuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

Stub.exe

Full Name

Stub.exe

EntryPoint

System.Void OK::main()

Scope Name

Stub.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v2.0.50727

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Stub

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

503

Main Method

System.Void OK::main()

Main IL Instruction Count

37

Main IL

ldsfld System.Boolean OK::HH brfalse.s IL_0086: call System.Void OK::ko() ldsfld System.IO.FileInfo OK::LO callvirt System.String System.IO.FileSystemInfo::get_FullName() call System.Object OK::HHK(System.String) pop <null> call My.MyComputer My.MyProject::get_Computer() callvirt Microsoft.VisualBasic.MyServices.RegistryProxy Microsoft.VisualBasic.Devices.ServerComputer::get_Registry() callvirt Microsoft.Win32.RegistryKey Microsoft.VisualBasic.MyServices.RegistryProxy::get_LocalMachine() ldsfld System.String OK::sf ldc.i4.1 <null> callvirt Microsoft.Win32.RegistryKey Microsoft.Win32.RegistryKey::OpenSubKey(System.String,System.Boolean) ldsfld System.String OK::RG ldsfld System.String OK::a callvirt System.Void Microsoft.Win32.RegistryKey::SetValue(System.String,System.Object) ldsfld Microsoft.VisualBasic.Devices.Computer OK::F callvirt Microsoft.VisualBasic.MyServices.RegistryProxy Microsoft.VisualBasic.Devices.ServerComputer::get_Registry() callvirt Microsoft.Win32.RegistryKey Microsoft.VisualBasic.MyServices.RegistryProxy::get_LocalMachine() ldsfld System.String OK::sf ldc.i4.1 <null> callvirt Microsoft.Win32.RegistryKey Microsoft.Win32.RegistryKey::OpenSubKey(System.String,System.Boolean) ldsfld System.String OK::RG ldsfld System.String OK::a callvirt System.Void Microsoft.Win32.RegistryKey::SetValue(System.String,System.Object) leave.s IL_0086: call System.Void OK::ko() dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.0 <null> ldloc.0 <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) ldloc.0 <null> stloc.1 <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0086: call System.Void OK::ko() call System.Void OK::ko() ret <null>

Module Name

Stub.exe

Full Name

Stub.exe

EntryPoint

System.Void OK::main()

Scope Name

Stub.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v2.0.50727

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Stub

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

<null>

Total Strings

503

Main Method

System.Void OK::main()

Main IL Instruction Count

37

Main IL

ldsfld System.Boolean OK::HH brfalse.s IL_0086: call System.Void OK::ko() ldsfld System.IO.FileInfo OK::LO callvirt System.String System.IO.FileSystemInfo::get_FullName() call System.Object OK::HHK(System.String) pop <null> call My.MyComputer My.MyProject::get_Computer() callvirt Microsoft.VisualBasic.MyServices.RegistryProxy Microsoft.VisualBasic.Devices.ServerComputer::get_Registry() callvirt Microsoft.Win32.RegistryKey Microsoft.VisualBasic.MyServices.RegistryProxy::get_LocalMachine() ldsfld System.String OK::sf ldc.i4.1 <null> callvirt Microsoft.Win32.RegistryKey Microsoft.Win32.RegistryKey::OpenSubKey(System.String,System.Boolean) ldsfld System.String OK::RG ldsfld System.String OK::a callvirt System.Void Microsoft.Win32.RegistryKey::SetValue(System.String,System.Object) ldsfld Microsoft.VisualBasic.Devices.Computer OK::F callvirt Microsoft.VisualBasic.MyServices.RegistryProxy Microsoft.VisualBasic.Devices.ServerComputer::get_Registry() callvirt Microsoft.Win32.RegistryKey Microsoft.VisualBasic.MyServices.RegistryProxy::get_LocalMachine() ldsfld System.String OK::sf ldc.i4.1 <null> callvirt Microsoft.Win32.RegistryKey Microsoft.Win32.RegistryKey::OpenSubKey(System.String,System.Boolean) ldsfld System.String OK::RG ldsfld System.String OK::a callvirt System.Void Microsoft.Win32.RegistryKey::SetValue(System.String,System.Object) leave.s IL_0086: call System.Void OK::ko() dup <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) stloc.0 <null> ldloc.0 <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception) ldloc.0 <null> stloc.1 <null> call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError() leave.s IL_0086: call System.Void OK::ko() call System.Void OK::ko() ret <null>

2bfbeaa25be3ec5055a3a53473bebc99 (49.15 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙