Malicious
Malicious

6bd9fff0aa36eda9657bd2c7c6e84fd5

PE Executable
MD5: 6bd9fff0aa36eda9657bd2c7c6e84fd5
Size: 37.38 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 6bd9fff0aa36eda9657bd2c7c6e84fd5
Sha1 880e2d2cbc4b577a371e43f6268754b8ebf591bf
Sha256 2876fd4c95181c6490ce8a6d416da734668a340959b6e932ada772d1c0e5c060
Sha384 6b40d3e96634b5779f4126240537dc03d2e00eb7bc8943e60feabd32d361e229aeacebd4517314df4e8b99a770ee93d3
Sha512 0bb342e5cec70a122b73c4a7661a302c881cfcc3bf542cfd6b9465535195a77bcb84c04b59be72a131c92da50bc6196bb5b8bc9b0730a8cb23697d074ca077f3
SSDeep 768:cLTp7hQmwxJ2/sKxcOMpbFJ9YrOMhN3xzB:cHp7hvwxc/bVMJFJ9YrOMPZB
TLSH 48F25C083B904226D6FF6FF95AB376021670F9039913DB8D0CD59AAB6F277C046147AB
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Mutex KzRn7huhuhuhuhuhuhu
Hosts xw.bidhuhuhuhuhuhuhuhuhuhuhu
Port 8huhuhuhu
KEY 123huhuhuhu
USBNM <Xwhuhuhuhu
family xhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
XW.exe
Full Name
XW.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
XW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XW
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
192
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
63
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::Hosts
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Hosts
ldsfld System.String Settings::Port
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Port
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00AB: call System.Void Stub.Helper::PreventSleep()
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.0 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__3()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldloc.0 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Module Name
XW.exe
Full Name
XW.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
XW.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XW
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
192
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
63
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::Hosts
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Hosts
ldsfld System.String Settings::Port
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Port
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00AB: call System.Void Stub.Helper::PreventSleep()
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.0 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__3()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldloc.0 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Mutex MUTEXmalicious
KzRn7huhuhuhuhuhuhu
CnC CNCmalicious
xw.huhuhuhu
CnC CNCmalicious
xw.huhuhuhu
CnC CNCmalicious
xw.huhuhuhu
CnC CNCmalicious
xw.huhuhuhu
CnC CNCmalicious
xw.huhuhuhu
CnC CNCmalicious
xw.huhuhuhu
CnC CNCmalicious
xw.huhuhuhu
Port PORTmalicious
8huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Mutex KzRn7huhuhuhuhuhuhu
Hosts xw.bidhuhuhuhuhuhuhuhuhuhuhu
Port 8huhuhuhu
KEY 123huhuhuhu
USBNM <Xwhuhuhuhu
family xhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Mutex MUTEXmalicious
KzRn7huhuhuhuhuhuhu
6bd9fff0aa36eda9657bd2c7c6e84fd5
CnC CNCmalicious
xw.huhuhuhu
6bd9fff0aa36eda9657bd2c7c6e84fd5
CnC CNCmalicious
xw.huhuhuhu
6bd9fff0aa36eda9657bd2c7c6e84fd5
CnC CNCmalicious
xw.huhuhuhu
6bd9fff0aa36eda9657bd2c7c6e84fd5
CnC CNCmalicious
xw.huhuhuhu
6bd9fff0aa36eda9657bd2c7c6e84fd5
CnC CNCmalicious
xw.huhuhuhu
6bd9fff0aa36eda9657bd2c7c6e84fd5
CnC CNCmalicious
xw.huhuhuhu
6bd9fff0aa36eda9657bd2c7c6e84fd5
CnC CNCmalicious
xw.huhuhuhu
6bd9fff0aa36eda9657bd2c7c6e84fd5
Port PORTmalicious
8huhuhuhu
6bd9fff0aa36eda9657bd2c7c6e84fd5
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙