Malicious
Malicious

PE Executable
MD5: 5e1583b953fbce83f90324558603902b
Size: 514.05 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5e1583b953fbce83f90324558603902b
Sha1 6e1017769ff31374f2396e030553402e9601c821
Sha256 7ed207c4ee2943946feaf7aa6d7a587d9fc156e1c5a7d8f5a2b8248bec6c671e
Sha384 d9459f1f4aba85bac9a6dc83be91ae51feb2622a0c5bff76156f89944d7fb1cee033acba4139a0c3edd5350424a4f3a2
Sha512 ce0a550191a9bd110e90f846127d407a5bfa4c8757844208d5b484594d48c21c7552ece602aa14648dadd8e30b8b37358207e0827c5029af05444fea996f257a
SSDeep 6144:UTEgdc0YNebGbXOsA6j1RdhqnphmsXkJl5Etqg+yw4gUcEFOb8F9hbQiZcTR3C:UTEgdfYlA6OphoE4Nyw+Vp30gcdC
TLSH 05B45B8123FC852BE1AE57BDE4B10425ABF4F407A667EB4F4940A2F92C567429E407F3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key DAE9E0huhuhuhuhuhuhuhuhuhuhu
Version 1huhuhuhu
Port 4Mekehuhuhuhuhuhuhu
Host 4Mekehuhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
SubDirectory Syhuhuhuhu
InstallName Windohuhuhuhuhuhuhu
Install 0huhuhuhu
Startup 0huhuhuhu
Mutex 79d78ahuhuhuhuhuhuhuhuhuhuhu
StartupKey Microhuhuhuhuhuhuhu
HideFile 1huhuhuhu
EnableLogger 1huhuhuhu
Tag 01huhuhuhu
LogDirectory Lhuhuhuhu
ServerSignature EJCtUGhuhuhuhuhuhuhuhuhuhuhu
ServerCertificate MIIE9Dhuhuhuhuhuhuhuhuhuhuhu
HideLogDirectory 1huhuhuhu
HideLogSubdirectory 1huhuhuhu
UnattendedMod 1huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void �槙↠ཇ⵰აࣻ䭤腛ⴶ滐죇㨉2瑝僋䄢ᙿ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
1552
Main Method
System.Void �槙↠ཇ⵰აࣻ䭤腛ⴶ滐죇㨉2瑝僋䄢ᙿ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void �槙↠ཇ⵰აࣻ䭤腛ⴶ滐죇㨉2瑝僋䄢ᙿ::቎밖䴶紾ꀮ飐ﵶ﹡脴혦鶲䃄ﬠ䞪정觥褄(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void �槙↠ཇ⵰აࣻ䭤腛ⴶ滐죇㨉2瑝僋䄢ᙿ::₅僥껇럥샐팘떔윩䑡☓搎펿訬馎⧈ಬ浦ⷋᕃ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 货ᶬ�컂鿛暆ʽვ⺘剴ꓷ斝읒ᴈĀꚵ萍::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void �槙↠ཇ⵰აࣻ䭤腛ⴶ滐죇㨉2瑝僋䄢ᙿ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
1552
Main Method
System.Void �槙↠ཇ⵰აࣻ䭤腛ⴶ滐죇㨉2瑝僋䄢ᙿ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void �槙↠ཇ⵰აࣻ䭤腛ⴶ滐죇㨉2瑝僋䄢ᙿ::቎밖䴶紾ꀮ飐ﵶ﹡脴혦鶲䃄ﬠ䞪정觥褄(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void �槙↠ཇ⵰აࣻ䭤腛ⴶ滐죇㨉2瑝僋䄢ᙿ::₅僥껇럥샐팘떔윩䑡☓搎펿訬馎⧈ಬ浦ⷋᕃ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 货ᶬ�컂鿛暆ʽვ⺘剴ꓷ斝읒ᴈĀꚵ萍::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
CnC CNCmalicious
4Mekehuhuhuhuhuhuhu
Port PORTmalicious
4Mekehuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key DAE9E0huhuhuhuhuhuhuhuhuhuhu
Version 1huhuhuhu
Port 4Mekehuhuhuhuhuhuhu
Host 4Mekehuhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
SubDirectory Syhuhuhuhu
InstallName Windohuhuhuhuhuhuhu
Install 0huhuhuhu
Startup 0huhuhuhu
Mutex 79d78ahuhuhuhuhuhuhuhuhuhuhu
StartupKey Microhuhuhuhuhuhuhu
HideFile 1huhuhuhu
EnableLogger 1huhuhuhu
Tag 01huhuhuhu
LogDirectory Lhuhuhuhu
ServerSignature EJCtUGhuhuhuhuhuhuhuhuhuhuhu
ServerCertificate MIIE9Dhuhuhuhuhuhuhuhuhuhuhu
HideLogDirectory 1huhuhuhu
HideLogSubdirectory 1huhuhuhu
UnattendedMod 1huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
4Mekehuhuhuhuhuhuhu
5e1583b953fbce83f90324558603902b
Port PORTmalicious
4Mekehuhuhuhuhuhuhu
5e1583b953fbce83f90324558603902b
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙