Malicious
Malicious

61c7797d09afde7a8690c677afe62bfe

PE Executable
MD5: 61c7797d09afde7a8690c677afe62bfe
Size: 46.08 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 61c7797d09afde7a8690c677afe62bfe
Sha1 1fd1d44aa586e52e393adb72c8a34c6f1f994588
Sha256 cc900a5a94804cc09fa2009055e3ef4aca1e3b18b32358e8d9884da4d374712b
Sha384 10ec20bbbfec8f799cb3a68b7615bd917296910b2e459a2279a9585050c6c874dc9852b2fe970042552dc7d5788396da
Sha512 17679e40c46bff34786843aff40f6b03f3f13d7bef894861a6c21486d88e6bf49884d2ef3d0193de16d2fe81603d90a77b52b5ab0c8e7f8f9aa6c884e850f937
SSDeep 768:pu2/0TckJ26WUsFvgmo2q70eqpG3jHuPIMzjbIgXBiSPvvR9uvBDZ6x:pu2/0TceH2PzM3M3bfXQS3vqZd6x
TLSH E3231A0037E9822BF2BE5FB4ACF26141467AF2637603D6492CC451DB5613BC6DA426FE
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) dUxLbmhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature clu+hehuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install File f8behuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts glahuhuhuhu
Ports 4huhuhuhu
Mutex QndMhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group Dehuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
f8betapp.exe
Full Name
f8betapp.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
f8betapp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
f8betapp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0043: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Module Name
f8betapp.exe
Full Name
f8betapp.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
f8betapp.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
f8betapp
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0043: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Key (AES_256) MUTEXmalicious
dUxLbmhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
glahuhuhuhu
Ports PORTmalicious
4huhuhuhu
Mutex MUTEXmalicious
QndMhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Key (AES_256) dUxLbmhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature clu+hehuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install File f8behuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts glahuhuhuhu
Ports 4huhuhuhu
Mutex QndMhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group Dehuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Key (AES_256) MUTEXmalicious
dUxLbmhuhuhuhuhuhuhuhuhuhuhu
61c7797d09afde7a8690c677afe62bfe
CnC CNCmalicious
glahuhuhuhu
61c7797d09afde7a8690c677afe62bfe
Ports PORTmalicious
4huhuhuhu
61c7797d09afde7a8690c677afe62bfe
Mutex MUTEXmalicious
QndMhuhuhuhu
61c7797d09afde7a8690c677afe62bfe
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙