Malicious
Malicious

4ab288fc3542766da93160e8d6e397eb

PE Executable
MD5: 4ab288fc3542766da93160e8d6e397eb
Size: 123.39 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 4ab288fc3542766da93160e8d6e397eb
Sha1 508ed858c5461060449d701def064079db84e566
Sha256 9a28edaa4609393576ddf09ad843c6e349ac88510e01f3c92039f88160845270
Sha384 e21360354c584882f5f1a10b076a96be65b59ba9c8eeda15f4c1fa1060bfe6cd3c857e51d981c0988869aca85bfe1575
Sha512 2eb20aaf584b5443c1ef4d949f7c371d35e1a8789dabfac26271517073e34c44ca403fcbf1edeac1d5ad1223d2522d902393fce36493d05cfd45dd74a1ccf27d
SSDeep 3072:FEFRh0auCcJVwDjwzTC2SCn/FtVQenIuxIGWsnRR9pLTf0vX3D:W3h0aMJ+Hw3Pgen79/svH
TLSH 1AC36C597753E0B2E44D2375623E377DCEB09E353CA0CAAFDF803D0A9E29190525A16B
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.00cfg
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet cahuhuhuhu
UserAgent
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet uppehuhuhuhu
UserAgent
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet othuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet othuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet cahuhuhuhu
UserAgent
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet uppehuhuhuhu
UserAgent
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet othuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: C:\Users\Administrator\Desktop\vdr1\Release\vdr1.pdb
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.00cfg
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet cahuhuhuhu
UserAgent
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet uppehuhuhuhu
UserAgent
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet othuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet othuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet cahuhuhuhu
UserAgent
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet uppehuhuhuhu
UserAgent
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhu
Botnet othuhuhuhu
UserAgent Mozillhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙