Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
AForge.Video.DirectShow.Properties.Resources.resources
camera
[NBF]root.Data
[NBF]root.Data-preview.png
AForge.Video.DirectShow.VideoCaptureDeviceForm.resources
ILRepack.List
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key D2973Fhuhuhuhuhuhuhuhuhuhuhu
Version 1huhuhuhu
Port YovngMhuhuhuhuhuhuhuhuhuhuhu
Host YovngMhuhuhuhuhuhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
Key Suhuhuhuhu
SubDirectory Clihuhuhuhu
InstallName 0huhuhuhu
Install 0huhuhuhu
Startup 0ff0cahuhuhuhuhuhuhuhuhuhuhu
Mutex Quasahuhuhuhuhuhuhu
StartupKey 0huhuhuhu
HideFile 0huhuhuhu
EnableLogger vichuhuhuhu
EncryptionKey Lhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
Key (AES_256) -huhuhuhu
Pastebin -huhuhuhu
ServerSignature 7IOXuChuhuhuhuhuhuhuhuhuhuhu
Install File Sbihuhuhuhu
Mutex cmdvhuhuhuhu
Group cmdvhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
Info
Remap: Mapped -> FileLayout (RAM only) as [Rebuild from dump]_53e7f278.exe
Module Name
Client
Full Name
Client
EntryPoint
System.Void tjvcxwkzlqyamklktgas.삡Ⴈ秦�흼췂₾鹛쬵鏉揤቞襡଒陸鞢ㄷԘ빀::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.7.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
1957
Main Method
System.Void tjvcxwkzlqyamklktgas.삡Ⴈ秦�흼췂₾鹛쬵鏉揤቞襡଒陸鞢ㄷԘ빀::Main(System.String[])
Main IL Instruction Count
20
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void tjvcxwkzlqyamklktgas.삡Ⴈ秦�흼췂₾鹛쬵鏉揤቞襡଒陸鞢ㄷԘ빀::푩׈䕷Ꮹ螫뛞볟寽㸗⹑嶉␸慚Ĵ帋䧠愢⋊(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void tjvcxwkzlqyamklktgas.삡Ⴈ秦�흼췂₾鹛쬵鏉揤቞襡଒陸鞢ㄷԘ빀::ꙕ疬붧�᤽눭螢㴨柕鮀ꖶ煤䷁顠菍﹁ꎋ䊶(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void tjvcxwkzlqyamklktgas.삡Ⴈ秦�흼췂₾鹛쬵鏉揤቞襡଒陸鞢ㄷԘ빀::�欓㩾ᭆ征쪜涧㿕쨦䆷銳鯶滊莔粊聋걓仪䛦()
newobj System.Void tjvcxwkzlqyamklktgas.盰織콀㝷㴫섬祣熝�ꔶᕳ莣¬泦꣤໻㘽〔::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void tjvcxwkzlqyamklktgas.삡Ⴈ秦�흼췂₾鹛쬵鏉揤቞襡଒陸鞢ㄷԘ빀::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.7.1.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
1957
Main Method
System.Void tjvcxwkzlqyamklktgas.삡Ⴈ秦�흼췂₾鹛쬵鏉揤቞襡଒陸鞢ㄷԘ빀::Main(System.String[])
Main IL Instruction Count
20
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void tjvcxwkzlqyamklktgas.삡Ⴈ秦�흼췂₾鹛쬵鏉揤቞襡଒陸鞢ㄷԘ빀::푩׈䕷Ꮹ螫뛞볟寽㸗⹑嶉␸慚Ĵ帋䧠愢⋊(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void tjvcxwkzlqyamklktgas.삡Ⴈ秦�흼췂₾鹛쬵鏉揤቞襡଒陸鞢ㄷԘ빀::ꙕ疬붧�᤽눭螢㴨柕鮀ꖶ煤䷁顠菍﹁ꎋ䊶(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.Void tjvcxwkzlqyamklktgas.삡Ⴈ秦�흼췂₾鹛쬵鏉揤቞襡଒陸鞢ㄷԘ빀::�欓㩾ᭆ征쪜涧㿕쨦䆷銳鯶滊莔粊聋걓仪䛦()
newobj System.Void tjvcxwkzlqyamklktgas.盰織콀㝷㴫섬祣熝�ꔶᕳ莣¬泦꣤໻㘽〔::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
CnC CNCmalicious
YovngMhuhuhuhuhuhuhuhuhuhuhu
Port PORTmalicious
YovngMhuhuhuhuhuhuhuhuhuhuhu
Key (AES_256) MUTEXmalicious
-huhuhuhu
Mutex MUTEXmalicious
cmdvhuhuhuhu
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙