Malicious
Malicious

PE Executable
MD5: 2d3218405a7d8094e4117904fd7b9a5b
Size: 308.89 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 2d3218405a7d8094e4117904fd7b9a5b
Sha1 b8b463023b8f81e3e5f0a829771e5347f03172a9
Sha256 8a2fecb22aeb3adcce1348ebf450f1b0d1f86ab3990ae1797dbf3bdf769c0296
Sha384 a87a44d64a99bd1d73ae5388f75166aefbebe6476d57140714c84b066fe83c46937ffc6e35f0e5eee757c0964bf08db3
Sha512 40659493fe106d70c7110b1b0f735b640354992e26273296db986a7ceb19b2d875a8de4ea09c86ac4a1acb5e4e768e85057e42d10fda8f8b9473faf204ff84cd
SSDeep 3072:+cZqf7D34qp/0+mAQkygQAQEgTLB1fA0PuTVAtkxzf3RQeqiOL2bBOA:+cZqf7DIqnyzjB1fA0GTV8kdwL
TLSH D3645A5833E8C910DA7F4775D861D67093B0BCA3A552E70B4FC4ACAB3D32740EA51AB6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Overlay_1394a0f1.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Form1.resources
Patterns.Properties.Resource1.resources
rootCert
Config. Field Value
[Configuration Module Name] Arghuhuhuhu
[Configuration Module Full Name] Arghuhuhuhu
IP 108.18huhuhuhuhuhuhu
ID 5DFFE0huhuhuhuhuhuhuhuhuhuhu
Message
Key
Version 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
[Configuration Module Name] Arghuhuhuhu
[Configuration Module Full Name] Arghuhuhuhu
Key
Version 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_1394a0f1.bin (1178 bytes)
Module Name
Steanings.exe
Full Name
Steanings.exe
EntryPoint
System.Void Program::Main()
Scope Name
Steanings.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Steanings
Assembly Version
1.1.21.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
301
Main Method
System.Void Program::Main()
Main IL Instruction Count
17
Main IL
nop <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0022: ret
stloc.0 <null>
nop <null>
nop <null>
leave.s IL_0022: ret
ret <null>
Module Name
Steanings.exe
Full Name
Steanings.exe
EntryPoint
System.Void Program::Main()
Scope Name
Steanings.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Steanings
Assembly Version
1.1.21.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
301
Main Method
System.Void Program::Main()
Main IL Instruction Count
17
Main IL
nop <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0022: ret
stloc.0 <null>
nop <null>
nop <null>
leave.s IL_0022: ret
ret <null>
Overlay_1394a0f1.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Form1.resources
Patterns.Properties.Resource1.resources
rootCert
Config. Field Value
[Configuration Module Name] Arghuhuhuhu
[Configuration Module Full Name] Arghuhuhuhu
IP 108.18huhuhuhuhuhuhu
ID 5DFFE0huhuhuhuhuhuhuhuhuhuhu
Message
Key
Version 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
[Configuration Module Name] Arghuhuhuhu
[Configuration Module Full Name] Arghuhuhuhu
Key
Version 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙