Malicious
Malicious

31f06fa6f01bbfe7e72a733fddb2652b

Share on LinkedIn
Print
PE Executable
MD5: 31f06fa6f01bbfe7e72a733fddb2652b
Size: 71.17 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 31f06fa6f01bbfe7e72a733fddb2652b
Sha1 0fc2401ee6e3d3cb890d6a1aa696b974f714e475
Sha256 20f21565d7e77f3b3b7247099af91da43dcde0078c173f8e6efc74a6d40b44c3
Sha384 9086abd37c9c9401fd083f121ee7469bb0257de4e7cc08d998779b59085d625a6744425c6c1e26e071a22ed0e1f3bea8
Sha512 170f45472ac231d41e6e9fe5b2c627996519edc1dd0b83749b6628a46b4756a92fc74fe0b29246bb8811e7777c300b09d8c6580b96da1a9a48d8994dcd65cb21
SSDeep 1536:/U3pN/xt5l1uqpl8+SFlUZCrYLn1RXJiC7mhaxtFjCz2Byr4CZbj0sjxeWg1leHa:/U3pN/xt5l1uqpl8+SFlUZCrYLn1RXJZ
TLSH B2632A4037FDD526F2FF4B74A8B22241467AFA677A37D60D0C84149E4622BC09A527FB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) ckQzTWhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE4Dhuhuhuhuhuhuhuhuhuhuhu
ServerSignature j0dCkthuhuhuhuhuhuhuhuhuhuhu
Install fhuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts 191.huhuhuhuhuhuhu
Ports 7huhuhuhu
Mutex UfdHhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group Dehuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
youtube.exe
Full Name
youtube.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
youtube.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
youtube
Assembly Version
7.16.638.9660
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
351
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
69
Main IL
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Reflection.Assembly Client.Program::CurrentDomain_AssemblyResolve(System.Object,System.ResolveEventArgs)
newobj System.Void System.ResolveEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_AssemblyResolve(System.ResolveEventHandler)
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
call System.Boolean Client.Program::IsDotNet48Installed()
brtrue IL_0041: ldc.i4.0
call System.Void Client.Program::BootstrapDotNet48()
leave IL_003A: ldc.i4.0
pop <null>
leave IL_003A: ldc.i4.0
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ret <null>
ldc.i4.0 <null>
stloc.0 <null>
br IL_0056: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0048: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0073: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0084: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0098: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00AC: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00CA: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_00CA: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
ldstr pkeenpghpkeocnndbeclgeojlbnoebcd
call System.Void Client.Helper.Methods::InjectExtension(System.String)
leave IL_00E4: nop
pop <null>
leave IL_00E4: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00F9: leave IL_0104
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_0104: ldc.i4 5000
pop <null>
leave IL_0104: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_00E4: nop
Module Name
youtube.exe
Full Name
youtube.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
youtube.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
youtube
Assembly Version
7.16.638.9660
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
351
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
69
Main IL
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Reflection.Assembly Client.Program::CurrentDomain_AssemblyResolve(System.Object,System.ResolveEventArgs)
newobj System.Void System.ResolveEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_AssemblyResolve(System.ResolveEventHandler)
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
call System.Boolean Client.Program::IsDotNet48Installed()
brtrue IL_0041: ldc.i4.0
call System.Void Client.Program::BootstrapDotNet48()
leave IL_003A: ldc.i4.0
pop <null>
leave IL_003A: ldc.i4.0
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ret <null>
ldc.i4.0 <null>
stloc.0 <null>
br IL_0056: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0048: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0073: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0084: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0098: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00AC: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00CA: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_00CA: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
ldstr pkeenpghpkeocnndbeclgeojlbnoebcd
call System.Void Client.Helper.Methods::InjectExtension(System.String)
leave IL_00E4: nop
pop <null>
leave IL_00E4: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00F9: leave IL_0104
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_0104: ldc.i4 5000
pop <null>
leave IL_0104: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_00E4: nop
Key (AES_256) MUTEXmalicious
ckQzTWhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
191.huhuhuhuhuhuhu
Ports PORTmalicious
7huhuhuhu
Mutex MUTEXmalicious
UfdHhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙