Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key lRvnn8huhuhuhuhuhuhu
Version 1.huhuhuhu
Port 1huhuhuhu
Host 45.1huhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory Suhuhuhuhu
InstallName Clihuhuhuhu
Install 0huhuhuhu
Startup 0huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey Windhuhuhuhuhuhuhu
HideFile 0huhuhuhu
EnableLogger 1huhuhuhu
Tag Ofhuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::ㅑ廣ሇר뽣퀶ꗍ刡솜ꤐ臂墧䨫㒗ٳ拡�淃父(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean 䚠㆘龼㟋홡ౡ鍭敛ꗤꋑ㗥╠㳜飘�䍸ở::膓ힹ渣锍谹邨⻇坡ખ뚷뫃ꗘ㫯ꎅ褔⿸ᥭ()
brfalse.s IL_0040: call System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::鍙됫컣报톂߮琮핶飔�ἅ᜗꘨ꁧ䠠빙菷䎖䯏()
call System.Boolean 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::墆�尪᧖ꉲ艐후띢ﳬꃃ珈鬷ﱇ聶嗜殠↏氻弊()
brfalse.s IL_0040: call System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::鍙됫컣报톂߮琮핶飔�ἅ᜗꘨ꁧ䠠빙菷䎖䯏()
call System.Boolean 〮갪ᝉ␛谔侏䀃㨛꙲䉆ⲍ떿䩫꙯::get_Exiting()
brtrue.s IL_0040: call System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::鍙됫컣报톂߮琮핶飔�ἅ᜗꘨ꁧ䠠빙菷䎖䯏()
ldsfld 〮갪ᝉ␛谔侏䀃㨛꙲䉆ⲍ떿䩫꙯ 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::ℽ⚒�嗥ջ螓㴠ᚭ㹊뢚䘳랐䆹˔仞냹锻⺆�ﶟ
callvirt System.Void 〮갪ᝉ␛谔侏䀃㨛꙲䉆ⲍ떿䩫꙯::陸ꢵˑ䝺쫻囘퉧복⬚碇㞇漲폜܉亻翇Ὸ()
call System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::鍙됫컣报톂߮琮핶飔�ἅ᜗꘨ꁧ䠠빙菷䎖䯏()
call System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::㕆庝䉯婈�税簅垡�ꝡ糏⮬䍓䰃ⲕᠳ鱙()
ret <null>
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::ㅑ廣ሇר뽣퀶ꗍ刡솜ꤐ臂墧䨫㒗ٳ拡�淃父(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean 䚠㆘龼㟋홡ౡ鍭敛ꗤꋑ㗥╠㳜飘�䍸ở::膓ힹ渣锍谹邨⻇坡ખ뚷뫃ꗘ㫯ꎅ褔⿸ᥭ()
brfalse.s IL_0040: call System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::鍙됫컣报톂߮琮핶飔�ἅ᜗꘨ꁧ䠠빙菷䎖䯏()
call System.Boolean 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::墆�尪᧖ꉲ艐후띢ﳬꃃ珈鬷ﱇ聶嗜殠↏氻弊()
brfalse.s IL_0040: call System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::鍙됫컣报톂߮琮핶飔�ἅ᜗꘨ꁧ䠠빙菷䎖䯏()
call System.Boolean 〮갪ᝉ␛谔侏䀃㨛꙲䉆ⲍ떿䩫꙯::get_Exiting()
brtrue.s IL_0040: call System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::鍙됫컣报톂߮琮핶飔�ἅ᜗꘨ꁧ䠠빙菷䎖䯏()
ldsfld 〮갪ᝉ␛谔侏䀃㨛꙲䉆ⲍ떿䩫꙯ 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::ℽ⚒�嗥ջ螓㴠ᚭ㹊뢚䘳랐䆹˔仞냹锻⺆�ﶟ
callvirt System.Void 〮갪ᝉ␛谔侏䀃㨛꙲䉆ⲍ떿䩫꙯::陸ꢵˑ䝺쫻囘퉧복⬚碇㞇漲폜܉亻翇Ὸ()
call System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::鍙됫컣报톂߮琮핶飔�ἅ᜗꘨ꁧ䠠빙菷䎖䯏()
call System.Void 䔩༶뵝㢟⾌銖噯䡲콳薵諠摔砀䜏㔣ꊺꆇ韃쒞::㕆庝䉯婈�税簅垡�ꝡ糏⮬䍓䰃ⲕᠳ鱙()
ret <null>
CnC CNCmalicious
45.1huhuhuhuhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙