Malicious
Malicious

55719fe909adc02bb40109c79a1167d3

Share on LinkedIn
Print
PE Executable
MD5: 55719fe909adc02bb40109c79a1167d3
Size: 50.18 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 55719fe909adc02bb40109c79a1167d3
Sha1 c2b7156c92a29d099cf5e3b2e33f2e0997442b39
Sha256 e2ce5effecaa7e91d3d8c2adde74650077f51bd26b50cfa839996324bb58db3d
Sha384 f6bc556e439e8625b7dc57bc65df174adff79d6821ea4104fc153d1a92a4f8b74bdcb0578f05c01339511e9b7a8fb59f
Sha512 dec97064ffecaf2d5d355d433e98b478ee4bc4bc25b9c9f3bc7251a45c92de1d106dd2a48951006ccf98d8f39a147363896346c3c0878a5b44bfdb2ceb45ec62
SSDeep 1536:MozqME+8xUUhhdXhOubBs6mnNRvlvVX8Bjr0KmVcl:MozqME+QUUhhdpbBwRvPspYK8Y
TLSH 4C333D1437E9822BF2BD5F789CF21241827BE2672602D54A7CC801DB5B13BC797526EE
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) ampxUkhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature YdfoSvhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS thuhuhuhu
Anti-VM thuhuhuhu
Install File mkhuhuhuhu
Install-Folder %Aphuhuhuhu
Version 0.huhuhuhu
Hosts casihuhuhuhuhuhuhu
Ports 8huhuhuhu
Mutex fgygzhuhuhuhuhuhuhu
Delay 1huhuhuhu
Group casihuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
XyQXyMUgnFFx
Full Name
XyQXyMUgnFFx
EntryPoint
System.Void odIkFFOLsDP.cXwSVJjaDysRkuvJ::Main()
Scope Name
XyQXyMUgnFFx
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mko1
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
121
Main Method
System.Void odIkFFOLsDP.cXwSVJjaDysRkuvJ::Main()
Main IL Instruction Count
50
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::MvnnqGnOGLXgEHfN
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean odIkFFOLsDP.qyqOtgApMGl::rzqkgXbUtQuEYZ()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean gONtggrmAolPT.jGVJHcrKzqlt::RHEfOKkdqKH()
brtrue IL_0043: ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::UBUJEjDvpBYxD
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::UBUJEjDvpBYxD
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::SrOeYfWmitxZW
call System.Void gONtggrmAolPT.nhpVIpvJCrfhECX::kmyphQVYJvZOLv()
ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::SrOeYfWmitxZW
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::IfxKyhqZpArL
call System.Void ovAeWBrKvNd.mCcYnVgyCJsRRX::duWkojYAuxWc()
ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::IfxKyhqZpArL
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void gONtggrmAolPT.ijSrevwcOpfHvjm::nwArBquSjOkiFH()
call System.Boolean gONtggrmAolPT.ijSrevwcOpfHvjm::AtKkMHECcUlEAZ()
brfalse IL_0089: call System.Void gONtggrmAolPT.ijSrevwcOpfHvjm::nwArBquSjOkiFH()
call System.Void gONtggrmAolPT.wtGziOopJlaxfe::SDcImXocVcQCQG()
call System.Void gONtggrmAolPT.ijSrevwcOpfHvjm::nwArBquSjOkiFH()
leave IL_0099: call System.Boolean OOxeTWWlqqonFeBY.KVmxkryGlgKptl::get_IsConnected()
pop <null>
leave IL_0099: call System.Boolean OOxeTWWlqqonFeBY.KVmxkryGlgKptl::get_IsConnected()
call System.Boolean OOxeTWWlqqonFeBY.KVmxkryGlgKptl::get_IsConnected()
brtrue IL_00AD: newobj System.Void System.Random::.ctor()
call System.Void OOxeTWWlqqonFeBY.KVmxkryGlgKptl::WOXrcDEsBvv()
call System.Void OOxeTWWlqqonFeBY.KVmxkryGlgKptl::SbuTDsNufpe()
newobj System.Void System.Random::.ctor()
ldc.i4 2000
ldc.i4 5000
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: call System.Boolean OOxeTWWlqqonFeBY.KVmxkryGlgKptl::get_IsConnected()
Info
PE Detect: PeReader OK (file layout)
Module Name
XyQXyMUgnFFx
Full Name
XyQXyMUgnFFx
EntryPoint
System.Void odIkFFOLsDP.cXwSVJjaDysRkuvJ::Main()
Scope Name
XyQXyMUgnFFx
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mko1
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
121
Main Method
System.Void odIkFFOLsDP.cXwSVJjaDysRkuvJ::Main()
Main IL Instruction Count
50
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::MvnnqGnOGLXgEHfN
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean odIkFFOLsDP.qyqOtgApMGl::rzqkgXbUtQuEYZ()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean gONtggrmAolPT.jGVJHcrKzqlt::RHEfOKkdqKH()
brtrue IL_0043: ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::UBUJEjDvpBYxD
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::UBUJEjDvpBYxD
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::SrOeYfWmitxZW
call System.Void gONtggrmAolPT.nhpVIpvJCrfhECX::kmyphQVYJvZOLv()
ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::SrOeYfWmitxZW
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::IfxKyhqZpArL
call System.Void ovAeWBrKvNd.mCcYnVgyCJsRRX::duWkojYAuxWc()
ldsfld System.String odIkFFOLsDP.qyqOtgApMGl::IfxKyhqZpArL
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void gONtggrmAolPT.ijSrevwcOpfHvjm::nwArBquSjOkiFH()
call System.Boolean gONtggrmAolPT.ijSrevwcOpfHvjm::AtKkMHECcUlEAZ()
brfalse IL_0089: call System.Void gONtggrmAolPT.ijSrevwcOpfHvjm::nwArBquSjOkiFH()
call System.Void gONtggrmAolPT.wtGziOopJlaxfe::SDcImXocVcQCQG()
call System.Void gONtggrmAolPT.ijSrevwcOpfHvjm::nwArBquSjOkiFH()
leave IL_0099: call System.Boolean OOxeTWWlqqonFeBY.KVmxkryGlgKptl::get_IsConnected()
pop <null>
leave IL_0099: call System.Boolean OOxeTWWlqqonFeBY.KVmxkryGlgKptl::get_IsConnected()
call System.Boolean OOxeTWWlqqonFeBY.KVmxkryGlgKptl::get_IsConnected()
brtrue IL_00AD: newobj System.Void System.Random::.ctor()
call System.Void OOxeTWWlqqonFeBY.KVmxkryGlgKptl::WOXrcDEsBvv()
call System.Void OOxeTWWlqqonFeBY.KVmxkryGlgKptl::SbuTDsNufpe()
newobj System.Void System.Random::.ctor()
ldc.i4 2000
ldc.i4 5000
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: call System.Boolean OOxeTWWlqqonFeBY.KVmxkryGlgKptl::get_IsConnected()
Key (AES_256) MUTEXmalicious
ampxUkhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
casihuhuhuhuhuhuhu
Ports PORTmalicious
8huhuhuhu
Mutex MUTEXmalicious
fgygzhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙