Malicious
Malicious

746811e8d9d3a1a0ac533ee3f83871e7

PE Executable
MD5: 746811e8d9d3a1a0ac533ee3f83871e7
Size: 357.38 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 746811e8d9d3a1a0ac533ee3f83871e7
Sha1 eb1b8204485f4a526b81ba1d73fcf6087a359eeb
Sha256 de64e714d4f8376abe5295da25b7029c660e1b950e06b72152fde610943e6ebc
Sha384 fd11f4106bf422ab56f35e47dd1e0cff64300b307a236b63b9601d00095638a1956cb7a2be7a33af1c8e7d66b8b524be
Sha512 c2b50658d92270de0b651bf862214d6923b0c10db82a92f449a0c887a4defcb03cde4c64c3fa04bcbeec536cd56c7c81f8554be1f9fc8e70d2f436bb3a2b329f
SSDeep 6144:ufqQ4i1FFiEKAwpbYCGz7nLz06bx4owfah8TblNMt31CYq:opliVbYpn8C4owfaSdNMt31CYq
TLSH EC749C1333A8D93BD1FE173AF4360A184BB1D457B616F38B5A5A55B82D233868D903B3
PeID
Microsoft Visual C# / Basic .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key BO3REHhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port 3huhuhuhu
Host 3huhuhuhu
Conf. AES-Key BO3REHhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port 4huhuhuhu
Host windowhuhuhuhuhuhuhu
ReconnectDelay 2huhuhuhu
Key oXCnUihuhuhuhuhuhuhu
AuthKey h36LUNhuhuhuhuhuhuhuhuhuhuhu
SubDirectory uhuhuhuhu
InstallName jsthuhuhuhu
Install 0huhuhuhu
Startup 0huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey Windohuhuhuhuhuhuhu
HideFile 1huhuhuhu
EnableLogger 1huhuhuhu
Tag Kahuhuhuhu
LogDirectory ohuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 1huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::터솴䬑˦塩ᢄ苪貇胧�뗽䪡黁竪Ⰿ⽷Ɵ尠(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean 꿭ꒌ휚ﱘ�炢蟆瀟⚓搱‰箯ຎ�箩꼧::嶢戯�Ⰺ蔖彄娠ᚈ媊봜槬标략趪�쁅콠()
brfalse.s IL_0040: call System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::ퟶ畹玻ѯֹꟜ뼓餃瘥惉긲谼ܺﬤ쯡莂⾧ﻋ㤎()
call System.Boolean পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::흁儶栄郻鋐牘囔쁍䢃鞽㶺뜌폖㊥镔ꥨ降켱()
brfalse.s IL_0040: call System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::ퟶ畹玻ѯֹꟜ뼓餃瘥惉긲谼ܺﬤ쯡莂⾧ﻋ㤎()
call System.Boolean 雺⫾痹噴⟃Ⲹ╔퐵⢀잾㸊䅅竽뛮㕀躺ꋁ::get_Exiting()
brtrue.s IL_0040: call System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::ퟶ畹玻ѯֹꟜ뼓餃瘥惉긲谼ܺﬤ쯡莂⾧ﻋ㤎()
ldsfld 雺⫾痹噴⟃Ⲹ╔퐵⢀잾㸊䅅竽뛮㕀躺ꋁ পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::┽ᣠ禳ὼ쒠넠�ㆳ煼鰼첟듽ッ⎅먞ջ㛦룸
callvirt System.Void 雺⫾痹噴⟃Ⲹ╔퐵⢀잾㸊䅅竽뛮㕀躺ꋁ::꣥彩栣ퟣ꤬誝歕ࢦ㨣ක⟴鐞㤠놢斯좤ᦺԸ觪()
call System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::ퟶ畹玻ѯֹꟜ뼓餃瘥惉긲谼ܺﬤ쯡莂⾧ﻋ㤎()
call System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::❫Ꞃ砽对໨쵰挃ꧽ饌蔅践㥢影䟜뢝ꖙ槒业ꈿ()
ret <null>
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::터솴䬑˦塩ᢄ苪貇胧�뗽䪡黁竪Ⰿ⽷Ɵ尠(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean 꿭ꒌ휚ﱘ�炢蟆瀟⚓搱‰箯ຎ�箩꼧::嶢戯�Ⰺ蔖彄娠ᚈ媊봜槬标략趪�쁅콠()
brfalse.s IL_0040: call System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::ퟶ畹玻ѯֹꟜ뼓餃瘥惉긲谼ܺﬤ쯡莂⾧ﻋ㤎()
call System.Boolean পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::흁儶栄郻鋐牘囔쁍䢃鞽㶺뜌폖㊥镔ꥨ降켱()
brfalse.s IL_0040: call System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::ퟶ畹玻ѯֹꟜ뼓餃瘥惉긲谼ܺﬤ쯡莂⾧ﻋ㤎()
call System.Boolean 雺⫾痹噴⟃Ⲹ╔퐵⢀잾㸊䅅竽뛮㕀躺ꋁ::get_Exiting()
brtrue.s IL_0040: call System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::ퟶ畹玻ѯֹꟜ뼓餃瘥惉긲谼ܺﬤ쯡莂⾧ﻋ㤎()
ldsfld 雺⫾痹噴⟃Ⲹ╔퐵⢀잾㸊䅅竽뛮㕀躺ꋁ পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::┽ᣠ禳ὼ쒠넠�ㆳ煼鰼첟듽ッ⎅먞ջ㛦룸
callvirt System.Void 雺⫾痹噴⟃Ⲹ╔퐵⢀잾㸊䅅竽뛮㕀躺ꋁ::꣥彩栣ퟣ꤬誝歕ࢦ㨣ක⟴鐞㤠놢斯좤ᦺԸ觪()
call System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::ퟶ畹玻ѯֹꟜ뼓餃瘥惉긲谼ܺﬤ쯡莂⾧ﻋ㤎()
call System.Void পഅ⦉ꖨⓞ㏘琗醷㝪䇧꼴뷚荡ڻ糀횥귛譡::❫Ꞃ砽对໨쵰挃ꧽ饌蔅践㥢影䟜뢝ꖙ槒业ꈿ()
ret <null>
CnC CNCmalicious
windowhuhuhuhuhuhuhu
Port PORTmalicious
4huhuhuhu
CnC CNCmalicious
3huhuhuhu
Port PORTmalicious
3huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key BO3REHhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port 3huhuhuhu
Host 3huhuhuhu
Conf. AES-Key BO3REHhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port 4huhuhuhu
Host windowhuhuhuhuhuhuhu
ReconnectDelay 2huhuhuhu
Key oXCnUihuhuhuhuhuhuhu
AuthKey h36LUNhuhuhuhuhuhuhuhuhuhuhu
SubDirectory uhuhuhuhu
InstallName jsthuhuhuhu
Install 0huhuhuhu
Startup 0huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey Windohuhuhuhuhuhuhu
HideFile 1huhuhuhu
EnableLogger 1huhuhuhu
Tag Kahuhuhuhu
LogDirectory ohuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 1huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
windowhuhuhuhuhuhuhu
746811e8d9d3a1a0ac533ee3f83871e7
Port PORTmalicious
4huhuhuhu
746811e8d9d3a1a0ac533ee3f83871e7
CnC CNCmalicious
3huhuhuhu
746811e8d9d3a1a0ac533ee3f83871e7
Port PORTmalicious
3huhuhuhu
746811e8d9d3a1a0ac533ee3f83871e7
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙