Malicious
Malicious

4c3747305b868bc35cdc0c06783c2414

PE Executable
MD5: 4c3747305b868bc35cdc0c06783c2414
Size: 36.86 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 4c3747305b868bc35cdc0c06783c2414
Sha1 ea45acf7b04e2c0c2e350bbe6eec7e949b16ea16
Sha256 ff8d4e85afc851f980f7227ebfddcabf75926a6306d4355b1062f0070141c8eb
Sha384 1cea5e0794fdc62f5af52527941cd4249bb4dcbbb9c43c5985ba47d185d9a680ff0d94050f640de2858db59bd413d7b7
Sha512 09abbdaac7b97b0070676632468508abc79348ec8b45fd9b9159c835a39cdf1e0de30a89a3781523479b296bd177fe6be6e719d813b4b1f32618e15cc2d02d21
SSDeep 768:sLJau6SW06XPdxcOMqbFJ9YRaOMhr3xzC:slautWzXFVMuFJ9YRaOMdZC
TLSH 19F24D083BD44225D6FF7FFA59B371021670F9079913EB8D4CD89AAA6F27BC045143AA
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Mutex kvQXfhuhuhuhuhuhuhu
Hosts 151.huhuhuhuhuhuhu
Port 7huhuhuhu
KEY <V7PVhuhuhuhuhuhuhu
USBNM <Xwhuhuhuhu
family xhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
XWormClient.exe
Full Name
XWormClient.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
XWormClient.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XWormClient
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
192
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
63
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::Hosts
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Hosts
ldsfld System.String Settings::Port
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Port
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00AB: call System.Void Stub.Helper::PreventSleep()
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.0 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__3()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldloc.0 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
XWormClient.exe
Full Name
XWormClient.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
XWormClient.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XWormClient
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
192
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
63
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::Hosts
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Hosts
ldsfld System.String Settings::Port
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Port
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00AB: call System.Void Stub.Helper::PreventSleep()
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.0 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__3()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldloc.0 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Mutex MUTEXmalicious
kvQXfhuhuhuhuhuhuhu
CnC CNCmalicious
151.huhuhuhuhuhuhu
Port PORTmalicious
7huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Mutex kvQXfhuhuhuhuhuhuhu
Hosts 151.huhuhuhuhuhuhu
Port 7huhuhuhu
KEY <V7PVhuhuhuhuhuhuhu
USBNM <Xwhuhuhuhu
family xhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Mutex MUTEXmalicious
kvQXfhuhuhuhuhuhuhu
4c3747305b868bc35cdc0c06783c2414
CnC CNCmalicious
151.huhuhuhuhuhuhu
4c3747305b868bc35cdc0c06783c2414
Port PORTmalicious
7huhuhuhu
4c3747305b868bc35cdc0c06783c2414
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙