Malicious
Malicious

3d259d2be7a34743eaeff93861806160

PE Executable
MD5: 3d259d2be7a34743eaeff93861806160
Size: 71.17 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 3d259d2be7a34743eaeff93861806160
Sha1 12685d1cb9f073731ac27d49c445eb12bb321ce9
Sha256 8437f141b392c50cb27717fef260b9bc0509178eb7919afe96b637b30cdca5d8
Sha384 aee82003250caf6e19881ac3dc5898d4b6806c36ed9634c30dca08ffe4727b04ddee2f3fef88c726e0619d1f3bc91f52
Sha512 906e9b304f01271d54f3026b903226232859764fe420a76d6852125e1a6483cb95b53326fa3090887a165e530d5cd0752abf709649ac87ac744d3a449cba3328
SSDeep 1536:juyj9/r5zLCJPr/8Hj6rZ5i2KjgQsOxDpcT0jUOxwWxJwfCZbj2sjxeWg1leHMwU:juyj9/r5zLCJPr/8Hj6rZ5i2KjgQsOxU
TLSH 6A632A0437F9D526F2FF4BB8ACB122454A7AFA677933C60D0D84149E4622BC09A517FB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) V1dCbmhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE4Dhuhuhuhuhuhuhuhuhuhuhu
ServerSignature aNtAp6huhuhuhuhuhuhuhuhuhuhu
Install fhuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install File Schhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts 108.1huhuhuhuhuhuhu
Ports 6606huhuhuhuhuhuhu
Mutex ABPuhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group Dehuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
evagosto2exe.exe
Full Name
evagosto2exe.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
evagosto2exe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
evagosto2exe
Assembly Version
7.16.638.9660
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
351
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
69
Main IL
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Reflection.Assembly Client.Program::CurrentDomain_AssemblyResolve(System.Object,System.ResolveEventArgs)
newobj System.Void System.ResolveEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_AssemblyResolve(System.ResolveEventHandler)
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
call System.Boolean Client.Program::IsDotNet48Installed()
brtrue IL_0041: ldc.i4.0
call System.Void Client.Program::BootstrapDotNet48()
leave IL_003A: ldc.i4.0
pop <null>
leave IL_003A: ldc.i4.0
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ret <null>
ldc.i4.0 <null>
stloc.0 <null>
br IL_0056: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0048: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0073: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0084: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0098: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00AC: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00CA: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_00CA: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
ldstr pkeenpghpkeocnndbeclgeojlbnoebcd
call System.Void Client.Helper.Methods::InjectExtension(System.String)
leave IL_00E4: nop
pop <null>
leave IL_00E4: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00F9: leave IL_0104
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_0104: ldc.i4 5000
pop <null>
leave IL_0104: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_00E4: nop
Module Name
evagosto2exe.exe
Full Name
evagosto2exe.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
evagosto2exe.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
evagosto2exe
Assembly Version
7.16.638.9660
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
351
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
69
Main IL
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Reflection.Assembly Client.Program::CurrentDomain_AssemblyResolve(System.Object,System.ResolveEventArgs)
newobj System.Void System.ResolveEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_AssemblyResolve(System.ResolveEventHandler)
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
call System.Boolean Client.Program::IsDotNet48Installed()
brtrue IL_0041: ldc.i4.0
call System.Void Client.Program::BootstrapDotNet48()
leave IL_003A: ldc.i4.0
pop <null>
leave IL_003A: ldc.i4.0
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ret <null>
ldc.i4.0 <null>
stloc.0 <null>
br IL_0056: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0048: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0073: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0084: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0098: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00AC: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00CA: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_00CA: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
ldstr pkeenpghpkeocnndbeclgeojlbnoebcd
call System.Void Client.Helper.Methods::InjectExtension(System.String)
leave IL_00E4: nop
pop <null>
leave IL_00E4: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00F9: leave IL_0104
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_0104: ldc.i4 5000
pop <null>
leave IL_0104: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_00E4: nop
Key (AES_256) MUTEXmalicious
V1dCbmhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
108.1huhuhuhuhuhuhu
Ports PORTmalicious
6huhuhuhu
Ports PORTmalicious
7huhuhuhu
Ports PORTmalicious
8huhuhuhu
Mutex MUTEXmalicious
ABPuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Key (AES_256) V1dCbmhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE4Dhuhuhuhuhuhuhuhuhuhuhu
ServerSignature aNtAp6huhuhuhuhuhuhuhuhuhuhu
Install fhuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install File Schhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts 108.1huhuhuhuhuhuhu
Ports 6606huhuhuhuhuhuhu
Mutex ABPuhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group Dehuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Key (AES_256) MUTEXmalicious
V1dCbmhuhuhuhuhuhuhuhuhuhuhu
3d259d2be7a34743eaeff93861806160
CnC CNCmalicious
108.1huhuhuhuhuhuhu
3d259d2be7a34743eaeff93861806160
Ports PORTmalicious
6huhuhuhu
3d259d2be7a34743eaeff93861806160
Ports PORTmalicious
7huhuhuhu
3d259d2be7a34743eaeff93861806160
Ports PORTmalicious
8huhuhuhu
3d259d2be7a34743eaeff93861806160
Mutex MUTEXmalicious
ABPuhuhuhuhu
3d259d2be7a34743eaeff93861806160
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙