Malicious
Malicious

743759338b45950208ea9d6cb6a99aa1

Share on LinkedIn
Print
PE Executable
MD5: 743759338b45950208ea9d6cb6a99aa1
Size: 24.06 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 743759338b45950208ea9d6cb6a99aa1
Sha1 0784ebd2aa021e89f12a06a7345ae81556ac3a7a
Sha256 64d8f6456140746ac1e5131ab8ada166c62893d53e7daf3d6a829292a7cfefd8
Sha384 be4e59e55d32b4765d9774455a2cf3606138ba9a5a023d3d47a2db514fe9d48b1d56d9ea5b70771d1873c3578c8e6b86
Sha512 784fada240a0d93e0d88440376d1d48ec05d7f624724cbd6572d16d258e9d9a75b57f3c2765bdbb6c56aa23f1e59e4a90dfeba083edfa52478605d51b13c9d32
SSDeep 384:LweXCQIreJig/8Z7SS1fEBpng6tgL2IBPZVmRvR6JZlbw8hqIusZzZjyr:sLq411eRpcnumw
TLSH 4BB22B4E3FB98856C5AC17748AA5965003B4D1870423EE2FCCC550CBAFB3ADA5D4CAF9
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
victim_name [VN] Hahuhuhuhu
version [VR] 0huhuhuhu
executable_name [EXE] serhuhuhuhu
directory [DR] Thuhuhuhu
reg_key [RG] e5e212huhuhuhuhuhuhuhuhuhuhu
cnc_host [H] 5.tcphuhuhuhuhuhuhu
cnc_port [P] 1huhuhuhu
splitter [Y] |huhuhuhu
BD [BD] Fhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
is_startup_folder [IsF] Fhuhuhuhu
is_user_reg [Isu] Thuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
packet_size [b] 5huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
j.exe
Full Name
j.exe
EntryPoint
System.Void j.A::main()
Scope Name
j.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
j
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
214
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
j.exe
Full Name
j.exe
EntryPoint
System.Void j.A::main()
Scope Name
j.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
j
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
214
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
CnC CNCmalicious
5.tcphuhuhuhuhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙