Malicious
Malicious

30f23cd8c071deac110bbaa70e4260cc

PE Executable
MD5: 30f23cd8c071deac110bbaa70e4260cc
Size: 32.26 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 30f23cd8c071deac110bbaa70e4260cc
Sha1 9ec707497613b9efae6a7af45a01a597e23b831e
Sha256 54fced67df11a75293cb6620d57101aca7dea30fcafe9ff40df3626388328d9e
Sha384 260376850ef7a89b703667ee391991dd1bc7cf0fcc6a3210be4b1289b9f712cfbbc7331c3bcd1870a571dd7d5ee372d3
Sha512 625f129ea86ee9c4342a279f93f9206f415d23bd183b588b028fcfb3f96289b4e2a31c67dedaa4f9737cd985ead4ae25d706bea3d247c3d014844cfe7e4110b9
SSDeep 768:6Zarirnp7VJMzxn6zCJeRm/TPlvcKQmIDUu0tiQrfnj:F0pKkqJjQVkTbj
TLSH FEE21B6DFBE64466D1BD0AB64571950013B8E003E523F67E4ECA34E62B2B7D84B44DF2
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] Windowhuhuhuhuhuhuhu
cnc_host [H] az8huhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
Anti_CH Fhuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
USB_SP Thuhuhuhu
is_user_reg [Isu] Thuhuhuhu
cnc_port [P] 4huhuhuhu
reg_key [RG] c11854huhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] flyhuhuhuhu
version [VR] 0huhuhuhu
splitter [Y] Y262huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
241
Main Method
System.Void j.A::main()
Main IL Instruction Count
4
Main IL
nop <null>
call System.Void j.OK::ko()
nop <null>
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
241
Main Method
System.Void j.A::main()
Main IL Instruction Count
4
Main IL
nop <null>
call System.Void j.OK::ko()
nop <null>
ret <null>
CnC CNCmalicious
az8huhuhuhu
Port PORTmalicious
4huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] Windowhuhuhuhuhuhuhu
cnc_host [H] az8huhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
Anti_CH Fhuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
USB_SP Thuhuhuhu
is_user_reg [Isu] Thuhuhuhu
cnc_port [P] 4huhuhuhu
reg_key [RG] c11854huhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] flyhuhuhuhu
version [VR] 0huhuhuhu
splitter [Y] Y262huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
az8huhuhuhu
30f23cd8c071deac110bbaa70e4260cc
Port PORTmalicious
4huhuhuhu
30f23cd8c071deac110bbaa70e4260cc
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙