Malicious
Malicious

364546dc5ef5bac9c45058d02f7b5b1d

PE Executable
MD5: 364546dc5ef5bac9c45058d02f7b5b1d
Size: 56.32 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 364546dc5ef5bac9c45058d02f7b5b1d
Sha1 21e31b944bdb80f4fa4cf62d59af6dd2e55b092b
Sha256 c6022364b4690bc9ed47ad9c4f36828edb264479832eac03de5c146d65ca358f
Sha384 67a71cf26eddaf13f92b79d5c204c9167d232c6dfc0e3b54dd6b27abf5781271a4ab8e6ef931f51b8d413bbfce746c58
Sha512 178533ebf4dcbcad310bb240cbd4c17966ebe20a8a96fe83cfacd20ee28327b82b150ef40dbb9da347fe1ea983177ed299365d6dafb51bb705812434966f01f4
SSDeep 1536:g+pMDnE4uNRty4XXzdhDVwsNMDdXExI3pmjm:pMDnlYk4XxhDVwsNMDdXExI3pm
TLSH 73432744BFEA4A05E2BC8F3468F655150634BA63E532EB1F48D668DB17327C58C80FE6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] dllhuhuhuhu
cnc_host [H] 11.tchuhuhuhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
Anti_CH Thuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
USB_SP Fhuhuhuhu
is_user_reg [Isu] Thuhuhuhu
cnc_port [P] 1huhuhuhu
reg_key [RG] 95416ehuhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] Vihuhuhuhu
version [VR] <- NjRhuhuhuhuhuhuhuhuhuhuhu
splitter [Y] Y262huhuhuhu
MSGE Dihuhuhuhu
MSGT Thhuhuhuhu
MSGB Sorry,huhuhuhuhuhuhuhuhuhuhu
MSGSYM vbChuhuhuhu
OBITO Dihuhuhuhu
TSKE Dihuhuhuhu
TSK Wirehuhuhuhuhuhuhu
KAKASHI Enhuhuhuhu
AKATSUKI Dihuhuhuhu
CLEANSWEEP Dihuhuhuhu
PASTEE Dihuhuhuhu
PASTEBIN https:huhuhuhuhuhuhuhuhuhuhu
CLIP nhuhuhuhu
UAC Dihuhuhuhu
nowifi ohuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Info
PE Detect: PeReader OK (file layout)
Total Strings
539
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
539
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
CnC CNCmalicious
11.tchuhuhuhuhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] Thuhuhuhu
executable_name [EXE] dllhuhuhuhu
cnc_host [H] 11.tchuhuhuhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
Anti_CH Thuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
USB_SP Fhuhuhuhu
is_user_reg [Isu] Thuhuhuhu
cnc_port [P] 1huhuhuhu
reg_key [RG] 95416ehuhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] Vihuhuhuhu
version [VR] <- NjRhuhuhuhuhuhuhuhuhuhuhu
splitter [Y] Y262huhuhuhu
MSGE Dihuhuhuhu
MSGT Thhuhuhuhu
MSGB Sorry,huhuhuhuhuhuhuhuhuhuhu
MSGSYM vbChuhuhuhu
OBITO Dihuhuhuhu
TSKE Dihuhuhuhu
TSK Wirehuhuhuhuhuhuhu
KAKASHI Enhuhuhuhu
AKATSUKI Dihuhuhuhu
CLEANSWEEP Dihuhuhuhu
PASTEE Dihuhuhuhu
PASTEBIN https:huhuhuhuhuhuhuhuhuhuhu
CLIP nhuhuhuhu
UAC Dihuhuhuhu
nowifi ohuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
11.tchuhuhuhuhuhuhu
364546dc5ef5bac9c45058d02f7b5b1d
Port PORTmalicious
1huhuhuhu
364546dc5ef5bac9c45058d02f7b5b1d
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙