Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5: 350fd6f01bb9d90dd6e994314a26cbca
Size: 356.35 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 350fd6f01bb9d90dd6e994314a26cbca
Sha1 a636879bc217c5834cc538d8ea35041d427f94f0
Sha256 4ef44bf6815e78603aec5b480f43fa26d883897c88ced763565e912c38ac9639
Sha384 f6cb799a86fde9caff333310c6402ff058a352a1c98125c211af4ed80ea52f01fc32f9af1e3cba6e9cb0b29af5fd2b94
Sha512 0f55edf275ab87a7ae3ecb34c225065f7511e3c76e4c936d3632d0a2c2e9f53851a1547624be0bdbb9f7e6506d823653fe663850bc4ba1a32ef26d5ad75f28b4
SSDeep 6144:cV6bPXhLApfpWkfr1MhL1bIzdY08mcMo9wx22eJYOq:gmhApffrmtuzS08m2Kx22S/q
TLSH 41748D2373A8E93BD5BE9736E432061547B0D547BE16F38F9A5892B92D133868D403B3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key Ygi5HJhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port localhuhuhuhuhuhuhu
Host localhuhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory GOhuhuhuhu
InstallName DRIhuhuhuhu
Install 1huhuhuhu
Startup 1huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey DRIVhuhuhuhu
HideFile 0huhuhuhu
EnableLogger 1huhuhuhu
Tag Dhuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::큾똄৖羇힫缛�齯ﵿ찞㥡ꄃ檻秝彦ꕸ粐쐜㟬(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean ⭮憬ꂪㅳ経랬枹뚑⾿�⹫㇊뎂ඖꂥ効긝퍝쿎::��辙߸膯賵秓썆찥閿̲즓࢛¶䠾()
brfalse.s IL_0040: call System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::䴍ᐵ댻墊翞࣯峅꯿媪䘙贋疐괢픗ᴧ⿛䆥薵()
call System.Boolean 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::䙵纝뺽櫎炊㻔㱮뿋运굂硑䳎書搗떸◫()
brfalse.s IL_0040: call System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::䴍ᐵ댻墊翞࣯峅꯿媪䘙贋疐괢픗ᴧ⿛䆥薵()
call System.Boolean 衦얡郏똼弟加ͽᨾ緐뒉萗揅ꃈ✾櫂홊玤탞䆻::get_Exiting()
brtrue.s IL_0040: call System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::䴍ᐵ댻墊翞࣯峅꯿媪䘙贋疐괢픗ᴧ⿛䆥薵()
ldsfld 衦얡郏똼弟加ͽᨾ緐뒉萗揅ꃈ✾櫂홊玤탞䆻 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::躥欽ۺ᳏Ꮂᑓ�㽯ઁ깛ꭔ꾸쉪뤡䌄켹ᠡ
callvirt System.Void 衦얡郏똼弟加ͽᨾ緐뒉萗揅ꃈ✾櫂홊玤탞䆻::蓑恌䱛ሳṀ샥淒䒂뾡褑쩎볎곀婧槆索慕傔()
call System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::䴍ᐵ댻墊翞࣯峅꯿媪䘙贋疐괢픗ᴧ⿛䆥薵()
call System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::ᕢ»崾ꄼ꺒ꡲ썮弖て驊튣媡↷〒毰੩굍ǭ()
ret <null>
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::큾똄৖羇힫缛�齯ﵿ찞㥡ꄃ檻秝彦ꕸ粐쐜㟬(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean ⭮憬ꂪㅳ経랬枹뚑⾿�⹫㇊뎂ඖꂥ効긝퍝쿎::��辙߸膯賵秓썆찥閿̲즓࢛¶䠾()
brfalse.s IL_0040: call System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::䴍ᐵ댻墊翞࣯峅꯿媪䘙贋疐괢픗ᴧ⿛䆥薵()
call System.Boolean 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::䙵纝뺽櫎炊㻔㱮뿋运굂硑䳎書搗떸◫()
brfalse.s IL_0040: call System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::䴍ᐵ댻墊翞࣯峅꯿媪䘙贋疐괢픗ᴧ⿛䆥薵()
call System.Boolean 衦얡郏똼弟加ͽᨾ緐뒉萗揅ꃈ✾櫂홊玤탞䆻::get_Exiting()
brtrue.s IL_0040: call System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::䴍ᐵ댻墊翞࣯峅꯿媪䘙贋疐괢픗ᴧ⿛䆥薵()
ldsfld 衦얡郏똼弟加ͽᨾ緐뒉萗揅ꃈ✾櫂홊玤탞䆻 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::躥欽ۺ᳏Ꮂᑓ�㽯ઁ깛ꭔ꾸쉪뤡䌄켹ᠡ
callvirt System.Void 衦얡郏똼弟加ͽᨾ緐뒉萗揅ꃈ✾櫂홊玤탞䆻::蓑恌䱛ሳṀ샥淒䒂뾡褑쩎볎곀婧槆索慕傔()
call System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::䴍ᐵ댻墊翞࣯峅꯿媪䘙贋疐괢픗ᴧ⿛䆥薵()
call System.Void 䲺泚꿀ൟ™堭摫ҿ癜๭耪ꟈ㖳뷙ꋙ涻퓂異::ᕢ»崾ꄼ꺒ꡲ썮弖て驊튣媡↷〒毰੩굍ǭ()
ret <null>
CnC CNCmalicious
localhuhuhuhuhuhuhu
Port PORTmalicious
localhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙