Malicious
PE Executable
MD5: 3c7fc20755929c8cde6b41da7767214f
Size: 38.91 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 3c7fc20755929c8cde6b41da7767214f |
| Sha1 | 9c66b95178c80f888f0e201352f5e03e440eb168 |
| Sha256 | 61b1bf909875d0ae463f2f5351e2b5f2c969abe95150a805d73a96dcbb651379 |
| Sha384 | fcfcdcdb7f6e5b9f615cc08ad653160defe7aa5484dc7674cffa71bd418eef89670f065bd08d997fc3822dacbc3d8189 |
| Sha512 | 75622f53487343c22f7bb79d04d06b731b1ab5162754766e8b8e2e33c730b0844ee131f7c8e2085725d6ffa90c82d788b7fec02153e8d42956881314298db081 |
| SSDeep | 384:X7DC9cMCcE84mr1H2bnTn8QHmp2M7739393bayse6QxnC7O+WRl3uuhGfrNP7UUq:XnCIcE8r1WbTpwFRbJpB+WWP7L/1Xj+ |
| TLSH | E7033908B7F84965F2FE5B7D8DB582004335FA579D22C79E1EC4508F5A63B88CA24FA1 |
| Config. Field | Value |
|---|---|
| Key (AES_256) | TXlTdXhuhuhuhuhuhuhuhuhuhuhu |
| Pastebin | -huhuhuhu |
| Install | fhuhuhuhu |
| Install File | Asynhuhuhuhu |
| Install-Folder | %Cerhuhuhuhuhuhuhu |
| Version | 0.huhuhuhu |
| Hosts | atadrehuhuhuhuhuhuhu |
| Mutex | Aphuhuhuhu |
| Delay | 0huhuhuhu |
| Group | Tehuhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | |
| Module Name | PhishingRAT.exe |
| Full Name | PhishingRAT.exe |
| EntryPoint | System.Void Client.Program::Main() |
| Scope Name | PhishingRAT.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | PhishingRAT |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 245 |
| Main Method | System.Void Client.Program::Main() |
| Main IL Instruction Count | 101 |
| Main IL | |
Key (AES_256)
MUTEXmalicious
TXlTdXhuhuhuhuhuhuhuhuhuhuhu
CnC
CNCmalicious
atadrehuhuhuhuhuhuhu
Mutex
MUTEXmalicious
Aphuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential