Malicious
Malicious

798d6bd179c9aa369aa4bce084265ce0

PE Executable
MD5: 798d6bd179c9aa369aa4bce084265ce0
Size: 40.96 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 798d6bd179c9aa369aa4bce084265ce0
Sha1 0ec61ca7b9a28ec2eabcba081c7d913645068115
Sha256 1ed0a0d1ec52bd6ef0635b0aaa0eb44550bb8d03e67f1cd08eb041e3ba128c01
Sha384 f5553e010617b5544776c7e58a4ba82759cc08dc3c59b591cb411fdcb93cc200dc6f69c768d8b55b751c3130ccaff67c
Sha512 729084673a6625a69068ad57cf55dc08dfd86b0d349ecb183d3d4357b933b1ed00026dbb9ce32213406cbe493848568414f8c00fec23f345e3aea0669a15b059
SSDeep 768:MDmoRDHj4qrIYH1p/SDVo03vaBM4F/93mOO+hqmGnN:MDmoRDHlkYHb/ea03vMF/937O+wrN
TLSH 2E034C4877E00625EAFF6FF919F362020631F5075913D7AE0CE59A5B2B57B84CA013EA
PeID
.NET executableMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Mutex MFsde0huhuhuhuhuhuhuhuhuhuhu
KEY MFsde0huhuhuhuhuhuhuhuhuhuhu
USBNM HT+7eAhuhuhuhuhuhuhuhuhuhuhu
family xhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Paste.exe
Full Name
Paste.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
Paste.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Paste
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
219
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
114
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
ldsfld System.String Settings::PasteUrl
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::PasteUrl
ldsfld System.String Settings::BTC
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::BTC
ldsfld System.String Settings::ETH
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::ETH
ldsfld System.String Settings::TRC
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::TRC
ldsfld System.String Settings::Token
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Token
ldsfld System.String Settings::ChatID
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::ChatID
leave.s IL_00EE: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.3 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_00EE: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00FB: ldsfld System.String Settings::PasteUrl
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Settings::PasteUrl
call System.String Stub.Main::DownloadStr(System.String)
stloc.0 <null>
ldloc.0 <null>
ldc.i4.1 <null>
newarr System.Char
stloc.s V_4
ldloc.s V_4
ldc.i4.0 <null>
ldc.i4.s 58
stelem.i2 <null>
ldloc.s V_4
callvirt System.String[] System.String::Split(System.Char[])
ldc.i4.0 <null>
ldelem.ref <null>
stsfld System.String Settings::Host
ldloc.0 <null>
ldc.i4.1 <null>
newarr System.Char
stloc.s V_4
ldloc.s V_4
ldc.i4.0 <null>
ldc.i4.s 58
stelem.i2 <null>
ldloc.s V_4
callvirt System.String[] System.String::Split(System.Char[])
ldc.i4.1 <null>
ldelem.ref <null>
stsfld System.String Settings::Port
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
call System.Void Stub.Main::SendBot()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__3()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__4()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.2 <null>
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.2 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.2 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Module Name
Paste.exe
Full Name
Paste.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
Paste.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Paste
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
219
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
114
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
ldsfld System.String Settings::PasteUrl
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::PasteUrl
ldsfld System.String Settings::BTC
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::BTC
ldsfld System.String Settings::ETH
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::ETH
ldsfld System.String Settings::TRC
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::TRC
ldsfld System.String Settings::Token
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Token
ldsfld System.String Settings::ChatID
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::ChatID
leave.s IL_00EE: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.3 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_00EE: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00FB: ldsfld System.String Settings::PasteUrl
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Settings::PasteUrl
call System.String Stub.Main::DownloadStr(System.String)
stloc.0 <null>
ldloc.0 <null>
ldc.i4.1 <null>
newarr System.Char
stloc.s V_4
ldloc.s V_4
ldc.i4.0 <null>
ldc.i4.s 58
stelem.i2 <null>
ldloc.s V_4
callvirt System.String[] System.String::Split(System.Char[])
ldc.i4.0 <null>
ldelem.ref <null>
stsfld System.String Settings::Host
ldloc.0 <null>
ldc.i4.1 <null>
newarr System.Char
stloc.s V_4
ldloc.s V_4
ldc.i4.0 <null>
ldc.i4.s 58
stelem.i2 <null>
ldloc.s V_4
callvirt System.String[] System.String::Split(System.Char[])
ldc.i4.1 <null>
ldelem.ref <null>
stsfld System.String Settings::Port
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
call System.Void Stub.Main::SendBot()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__3()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__4()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.2 <null>
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.2 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.2 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Mutex MUTEXmalicious
MFsde0huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Mutex MFsde0huhuhuhuhuhuhuhuhuhuhu
KEY MFsde0huhuhuhuhuhuhuhuhuhuhu
USBNM HT+7eAhuhuhuhuhuhuhuhuhuhuhu
family xhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Mutex MUTEXmalicious
MFsde0huhuhuhuhuhuhuhuhuhuhu
798d6bd179c9aa369aa4bce084265ce0
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙