Malicious
Malicious

61480a155193ab1d60ede49b5fe13556

Share on LinkedIn
Print
PE Executable
MD5: 61480a155193ab1d60ede49b5fe13556
Size: 47.1 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 61480a155193ab1d60ede49b5fe13556
Sha1 36bebfe8d53c60e5b97c084bf6e0b4bb94e457fd
Sha256 791c80619bb5c1dcd0a560c419b8e32885d074c82f626a1f35d4f477a45eb344
Sha384 7ce9d33668a8793597d082cfd0444b556589eeb60c6ea0d573f6f09bcda5d369b99798c9d1fa8c1714162c00879b8dda
Sha512 0d5cb4d780dcaf1e814e8adb21298257491e3341dd89a058f32afd54cd05edcb28aeb7675f313681354eb8f308d3cc45af0ef88b991400c351c3d0c8c4770e21
SSDeep 768:LqdpXbXX0fIAkOicvHk3eHlWMPbPgF0qp1ufQPpGYQvbPNPYI6OCC2tYcFmVc6K:LtIAXvZH0ub4Frp1uf4f0p6OnKmVcl
TLSH F7232C003BE98126E1FE5FB8ACF1514187BAE6633603D65E3CC841D75B137C6CA52AE6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) ejZ6S0huhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature lQ8uyWhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install File svchuhuhuhu
Install-Folder %Aphuhuhuhu
Version 0.huhuhuhu
Hosts bfhuhuhuhu
Ports 4huhuhuhu
Mutex mkhuhuhuhu
Delay 5huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
130
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
53
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br.s IL_0012: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0004: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue.s IL_002C: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue.s IL_003A: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse.s IL_004B: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse.s IL_005C: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse.s IL_0074: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse.s IL_0074: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
newobj System.Void Client.Helper.CheckMiner::.ctor()
call System.String Client.Helper.CheckMiner::GetProcess()
pop <null>
leave.s IL_0089: call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
pop <null>
leave.s IL_0089: call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue.s IL_009A: newobj System.Void System.Random::.ctor()
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
newobj System.Void System.Random::.ctor()
ldc.i4 1000
ldc.i4 5000
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0089: call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
130
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
53
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br.s IL_0012: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0004: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue.s IL_002C: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue.s IL_003A: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse.s IL_004B: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse.s IL_005C: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse.s IL_0074: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse.s IL_0074: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
newobj System.Void Client.Helper.CheckMiner::.ctor()
call System.String Client.Helper.CheckMiner::GetProcess()
pop <null>
leave.s IL_0089: call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
pop <null>
leave.s IL_0089: call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue.s IL_009A: newobj System.Void System.Random::.ctor()
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
newobj System.Void System.Random::.ctor()
ldc.i4 1000
ldc.i4 5000
callvirt System.Int32 System.Random::Next(System.Int32,System.Int32)
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0089: call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
Key (AES_256) MUTEXmalicious
ejZ6S0huhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
bfhuhuhuhu
Ports PORTmalicious
4huhuhuhu
Mutex MUTEXmalicious
mkhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙