Malicious
Malicious

881ac6e7cf0a683fd568c417d1dfd660

PE Executable
MD5: 881ac6e7cf0a683fd568c417d1dfd660
Size: 48.64 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 881ac6e7cf0a683fd568c417d1dfd660
Sha1 2bf574539b248e1f0efad309124587ddbf066140
Sha256 07fe77bfc9a7471d905aa46794dea97ecde0f3b1c167fce78eb79700245d0010
Sha384 131125c1190386832ad6860ae55e2d13fe6faa0f34a8aae70674d28a3bab551c0032be6d3d8159b7b64a13ae484d81a0
Sha512 e0d473d39959e4770aaf04a2c35ee80f5a8c60350378b118fdb502eb64a767f6904c62dae753c6406b8736c73bab352598c1dccff3b640ecad475e6ce240947c
SSDeep 768:guYHKTsufqG9vSLjWUvlPRmo2qbUmlegLAYsGZ9hiHPIzvcxD20brqmAADlQHOzG:guYHKTsjMvSX2ZngLljLYZbrqm9DOuzG
TLSH B2232A0077E9C22AF2BE4F7899F222458677F6672603D64E1CC441975B13FC29A426FE
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) eEpZU0huhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature le/vE4huhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS thuhuhuhu
Anti-VM thuhuhuhu
Install File Chromhuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts vn78huhuhuhu
Ports 4huhuhuhu
Mutex cxldhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group vn78huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
peWocCsaZfe
Full Name
peWocCsaZfe
EntryPoint
System.Void NYdQNkgqsBcRjJaki.tsQjVGtIbCXD::Main()
Scope Name
peWocCsaZfe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mko2
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void NYdQNkgqsBcRjJaki.tsQjVGtIbCXD::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::BaYrMqRGVCnXn
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::UZjzrCeAtZKwg()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean ZdShIsfhPnqLyqUhT.NxuSymYJgVXRV::EovrlcixKmrrGn()
brtrue IL_0043: ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::HQMDhekYXLWIn
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::HQMDhekYXLWIn
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::NCggsGHvrvjHlm
call System.Void ZdShIsfhPnqLyqUhT.WjGPaJvnvFBwugf::ijiZDOPYtSQ()
ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::NCggsGHvrvjHlm
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::jzoQrmMkbeAfH
call System.Void WOWLrUDyAgRM.PysOpZGMUQlsiG::RjkutpCgvTC()
ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::jzoQrmMkbeAfH
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void ZdShIsfhPnqLyqUhT.eENiRTtFPNTYg::HwoLDfLuKSVxWF()
call System.Boolean ZdShIsfhPnqLyqUhT.eENiRTtFPNTYg::Xpspwnfwuf()
brfalse IL_0089: call System.Void ZdShIsfhPnqLyqUhT.eENiRTtFPNTYg::HwoLDfLuKSVxWF()
call System.Void ZdShIsfhPnqLyqUhT.IrGEORnjoMPgossvE::FzBbmESaMpAl()
call System.Void ZdShIsfhPnqLyqUhT.eENiRTtFPNTYg::HwoLDfLuKSVxWF()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean NgLqldVNYL.aIrGXYeECQhyM::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void NgLqldVNYL.aIrGXYeECQhyM::sJwiBoqYGAK()
call System.Void NgLqldVNYL.aIrGXYeECQhyM::FVyKjrXzCc()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
peWocCsaZfe
Full Name
peWocCsaZfe
EntryPoint
System.Void NYdQNkgqsBcRjJaki.tsQjVGtIbCXD::Main()
Scope Name
peWocCsaZfe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
mko2
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void NYdQNkgqsBcRjJaki.tsQjVGtIbCXD::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::BaYrMqRGVCnXn
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::UZjzrCeAtZKwg()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean ZdShIsfhPnqLyqUhT.NxuSymYJgVXRV::EovrlcixKmrrGn()
brtrue IL_0043: ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::HQMDhekYXLWIn
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::HQMDhekYXLWIn
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::NCggsGHvrvjHlm
call System.Void ZdShIsfhPnqLyqUhT.WjGPaJvnvFBwugf::ijiZDOPYtSQ()
ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::NCggsGHvrvjHlm
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::jzoQrmMkbeAfH
call System.Void WOWLrUDyAgRM.PysOpZGMUQlsiG::RjkutpCgvTC()
ldsfld System.String NYdQNkgqsBcRjJaki.sVXwyYKiXFPZgQ::jzoQrmMkbeAfH
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void ZdShIsfhPnqLyqUhT.eENiRTtFPNTYg::HwoLDfLuKSVxWF()
call System.Boolean ZdShIsfhPnqLyqUhT.eENiRTtFPNTYg::Xpspwnfwuf()
brfalse IL_0089: call System.Void ZdShIsfhPnqLyqUhT.eENiRTtFPNTYg::HwoLDfLuKSVxWF()
call System.Void ZdShIsfhPnqLyqUhT.IrGEORnjoMPgossvE::FzBbmESaMpAl()
call System.Void ZdShIsfhPnqLyqUhT.eENiRTtFPNTYg::HwoLDfLuKSVxWF()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean NgLqldVNYL.aIrGXYeECQhyM::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void NgLqldVNYL.aIrGXYeECQhyM::sJwiBoqYGAK()
call System.Void NgLqldVNYL.aIrGXYeECQhyM::FVyKjrXzCc()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Key (AES_256) MUTEXmalicious
eEpZU0huhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
vn78huhuhuhu
Ports PORTmalicious
4huhuhuhu
Mutex MUTEXmalicious
cxldhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Key (AES_256) eEpZU0huhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature le/vE4huhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS thuhuhuhu
Anti-VM thuhuhuhu
Install File Chromhuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts vn78huhuhuhu
Ports 4huhuhuhu
Mutex cxldhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group vn78huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Key (AES_256) MUTEXmalicious
eEpZU0huhuhuhuhuhuhuhuhuhuhu
881ac6e7cf0a683fd568c417d1dfd660
CnC CNCmalicious
vn78huhuhuhu
881ac6e7cf0a683fd568c417d1dfd660
Ports PORTmalicious
4huhuhuhu
881ac6e7cf0a683fd568c417d1dfd660
Mutex MUTEXmalicious
cxldhuhuhuhu
881ac6e7cf0a683fd568c417d1dfd660
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙