Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
PeID
Microsoft Visual C# / Basic .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key MGcPZQhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port alexihuhuhuhuhuhuhu
Host alexihuhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory Suhuhuhuhu
InstallName Clihuhuhuhu
Install 0huhuhuhu
Startup 1huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey Quasahuhuhuhuhuhuhu
HideFile 0huhuhuhu
EnableLogger 1huhuhuhu
Tag ahuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::⫌竺촚鹜몃냶쳷蒢䨍꾚钥ᬽ펷姸붛৅(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean 綐医╽诘歲丸褟書늧怤뻮ᄘ 슆辮㲼�㎒::棙Ო뚭쉐툻♶ㅣ蜕楲䌜柸戰롢ꁲꫠ痭⸅()
brfalse.s IL_0040: call System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::딤ŏ鬹虉ʤﶼ캯炵㕧긄ⵤ쐺슒+你쀁뒡鳯懒()
call System.Boolean 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::뮅὚㏽苝踰㦵པퟗ雤弡풘筧䇹꒰()
brfalse.s IL_0040: call System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::딤ŏ鬹虉ʤﶼ캯炵㕧긄ⵤ쐺슒+你쀁뒡鳯懒()
call System.Boolean 㪹펅렃鰖�芝靅Ꞔ粒쉙ﳊ�닶馝ꏱ睂꽓뽽::get_Exiting()
brtrue.s IL_0040: call System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::딤ŏ鬹虉ʤﶼ캯炵㕧긄ⵤ쐺슒+你쀁뒡鳯懒()
ldsfld 㪹펅렃鰖�芝靅Ꞔ粒쉙ﳊ�닶馝ꏱ睂꽓뽽 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::楂甛쪭㘗ᶭ�㑓胫큝伬ꩺ燉㕉뾘寵꟭餴먳ࢬ
callvirt System.Void 㪹펅렃鰖�芝靅Ꞔ粒쉙ﳊ�닶馝ꏱ睂꽓뽽::鈃꫖髀‧뫱㽈债릒ৼ맀Ⴧ⢰繣᧸隬濩揕()
call System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::딤ŏ鬹虉ʤﶼ캯炵㕧긄ⵤ쐺슒+你쀁뒡鳯懒()
call System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::칫梏쬡꥿榜쁌∟朡거ꮶ⚠됓靎䨣⁳땂()
ret <null>
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::⫌竺촚鹜몃냶쳷蒢䨍꾚钥ᬽ펷姸붛৅(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean 綐医╽诘歲丸褟書늧怤뻮ᄘ 슆辮㲼�㎒::棙Ო뚭쉐툻♶ㅣ蜕楲䌜柸戰롢ꁲꫠ痭⸅()
brfalse.s IL_0040: call System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::딤ŏ鬹虉ʤﶼ캯炵㕧긄ⵤ쐺슒+你쀁뒡鳯懒()
call System.Boolean 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::뮅὚㏽苝踰㦵པퟗ雤弡풘筧䇹꒰()
brfalse.s IL_0040: call System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::딤ŏ鬹虉ʤﶼ캯炵㕧긄ⵤ쐺슒+你쀁뒡鳯懒()
call System.Boolean 㪹펅렃鰖�芝靅Ꞔ粒쉙ﳊ�닶馝ꏱ睂꽓뽽::get_Exiting()
brtrue.s IL_0040: call System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::딤ŏ鬹虉ʤﶼ캯炵㕧긄ⵤ쐺슒+你쀁뒡鳯懒()
ldsfld 㪹펅렃鰖�芝靅Ꞔ粒쉙ﳊ�닶馝ꏱ睂꽓뽽 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::楂甛쪭㘗ᶭ�㑓胫큝伬ꩺ燉㕉뾘寵꟭餴먳ࢬ
callvirt System.Void 㪹펅렃鰖�芝靅Ꞔ粒쉙ﳊ�닶馝ꏱ睂꽓뽽::鈃꫖髀‧뫱㽈债릒ৼ맀Ⴧ⢰繣᧸隬濩揕()
call System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::딤ŏ鬹虉ʤﶼ캯炵㕧긄ⵤ쐺슒+你쀁뒡鳯懒()
call System.Void 䘗ય梘㥬ꇔ膨鵋蠈늿螏঎ꤾ썁唖喢㙑葞::칫梏쬡꥿榜쁌∟朡거ꮶ⚠됓靎䨣⁳땂()
ret <null>
CnC CNCmalicious
alexihuhuhuhuhuhuhu
Port PORTmalicious
alexihuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙