Malicious
Malicious

4219f0af60e495329e4682f0f7c05a78

PE Executable
MD5: 4219f0af60e495329e4682f0f7c05a78
Size: 56.83 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 4219f0af60e495329e4682f0f7c05a78
Sha1 39d4b89d9c1286543852a48e52bbb765ce06812f
Sha256 5593d52e822e477bfb8abb394964779a43d177caf7e56c996918f92be750c2ec
Sha384 960ace3a3d584fd735d4b9e3789c70fe540d7213a3239b722a1086953522c067064ce04628207df11276076764a93fc3
Sha512 61798b44a20a16be1a2e5ae6d1c22bc9474fd1f61b4953a9d665b274a2bf7d3f00dcf04dbc81aa9136bd961d8fc1ff56763c03432769af9e1795ed26977c2cdd
SSDeep 1536:hfTgx0p7i8rv94NOeq2NbIsdewsasD7pbx:JgWYOL2NbI0ew4D7lx
TLSH 55432B143BE98126F1BE8F7898F661428675B6236513DA8E1CD411CB0A13BC5DE427FF
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) Z0xNQXhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature qFrZmjhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install File tele@ehuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts go8.plhuhuhuhuhuhuhu
Ports 44huhuhuhu
Mutex z9m0huhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group Dehuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
g8.exe
Full Name
g8.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
g8.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
g8
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
227
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
64
Main IL
ldc.i4.0 <null>
stloc.0 <null>
ldsfld System.String Client.Settings::Delay
ldloca.s V_0
call System.Boolean System.Int32::TryParse(System.String,System.Int32&)
brtrue IL_0015: ldc.i4.0
ldc.i4.0 <null>
stloc.0 <null>
ldc.i4.0 <null>
stloc.1 <null>
br IL_002A: ldloc.1
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.1 <null>
ldc.i4.1 <null>
add <null>
stloc.1 <null>
ldloc.1 <null>
ldloc.0 <null>
blt.s IL_001C: ldc.i4 1000
leave IL_0039: call System.Boolean Client.Settings::InitializeSettings()
pop <null>
leave IL_0039: call System.Boolean Client.Settings::InitializeSettings()
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0053: call System.Threading.Tasks.Task Client.Program::SendRequests()
ldstr Settings initialization failed. Exiting.
call System.Void System.Console::WriteLine(System.String)
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Threading.Tasks.Task Client.Program::SendRequests()
pop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0069: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_007D: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0091: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00AF: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_00AF: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
leave IL_00BF: nop
pop <null>
leave IL_00BF: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00D4: leave IL_00DF
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_00DF: ldc.i4 5000
pop <null>
leave IL_00DF: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_00BF: nop
Module Name
g8.exe
Full Name
g8.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
g8.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
g8
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
227
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
64
Main IL
ldc.i4.0 <null>
stloc.0 <null>
ldsfld System.String Client.Settings::Delay
ldloca.s V_0
call System.Boolean System.Int32::TryParse(System.String,System.Int32&)
brtrue IL_0015: ldc.i4.0
ldc.i4.0 <null>
stloc.0 <null>
ldc.i4.0 <null>
stloc.1 <null>
br IL_002A: ldloc.1
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.1 <null>
ldc.i4.1 <null>
add <null>
stloc.1 <null>
ldloc.1 <null>
ldloc.0 <null>
blt.s IL_001C: ldc.i4 1000
leave IL_0039: call System.Boolean Client.Settings::InitializeSettings()
pop <null>
leave IL_0039: call System.Boolean Client.Settings::InitializeSettings()
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0053: call System.Threading.Tasks.Task Client.Program::SendRequests()
ldstr Settings initialization failed. Exiting.
call System.Void System.Console::WriteLine(System.String)
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Threading.Tasks.Task Client.Program::SendRequests()
pop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0069: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_007D: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0091: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00AF: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_00AF: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
leave IL_00BF: nop
pop <null>
leave IL_00BF: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00D4: leave IL_00DF
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_00DF: ldc.i4 5000
pop <null>
leave IL_00DF: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_00BF: nop
Key (AES_256) MUTEXmalicious
Z0xNQXhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
gohuhuhuhu
CnC CNCmalicious
api.huhuhuhu
Ports PORTmalicious
4huhuhuhu
Ports PORTmalicious
8huhuhuhu
Mutex MUTEXmalicious
z9m0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Key (AES_256) Z0xNQXhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature qFrZmjhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install File tele@ehuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts go8.plhuhuhuhuhuhuhu
Ports 44huhuhuhu
Mutex z9m0huhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group Dehuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Key (AES_256) MUTEXmalicious
Z0xNQXhuhuhuhuhuhuhuhuhuhuhu
4219f0af60e495329e4682f0f7c05a78
CnC CNCmalicious
gohuhuhuhu
4219f0af60e495329e4682f0f7c05a78
CnC CNCmalicious
api.huhuhuhu
4219f0af60e495329e4682f0f7c05a78
Ports PORTmalicious
4huhuhuhu
4219f0af60e495329e4682f0f7c05a78
Ports PORTmalicious
8huhuhuhu
4219f0af60e495329e4682f0f7c05a78
Mutex MUTEXmalicious
z9m0huhuhuhu
4219f0af60e495329e4682f0f7c05a78
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙