Malicious
Malicious

PE Executable
MD5: 91fc160c3a2daa73e34828f3ea380060
Size: 356.35 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 91fc160c3a2daa73e34828f3ea380060
Sha1 7f6b26fceacd5961ba5d6765b04d6ce8bc3368c2
Sha256 b26df12d3e24ab67bb60e57976413340cb7d7421e7ccd893530c23f069c2e7a3
Sha384 47e199ccb74bac9cf11d608444e3368addd09e6c99c2da0ca6565c6c50a232ac4081706823b0b0c409927a81999e11aa
Sha512 ff9ba7bc1d3403b40491004dacb969765b707f9e8e26c77bdb3ed5b176cbbff4118a655758634c7095e0785312be0fc804ffcf469210c1aab00237b7f228fe31
SSDeep 6144:EN6bPXhLApfph5BS6kgOmbmOjMfeouxPYBNF0LsfOY+:wmhApzS6k3JgMfeoaPYfOLsfOY+
TLSH D1749D1337A4EE3BD1FE1736E43206090BB0D4677616E38B5A6A55B92D133868E913F3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key Vl6roDhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port 1huhuhuhu
Host 176.huhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory Suhuhuhuhu
InstallName Clihuhuhuhu
Install 0huhuhuhu
Startup 1huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey wihuhuhuhu
HideFile 0huhuhuhu
EnableLogger 0huhuhuhu
Tag Ofhuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::큐벆橿錓結宲啭泒ウ⛒ꮫ䢊瀠ᯮᢜ;궕(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean ༺欩䜰�띋Jꋢ�䐂픂摠䪍뉎뒫䕐⎇�::쏎眅㹈톫₝珄䟰῞鹜髪�磐㮔앲䆢됓㊕폢粠()
brfalse.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Boolean 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::粪㶨Ӕ蘇垦卯륔邙擷츏䋆煳ꫥ蹵ၷ뷫䛌횥똼ᠻ()
brfalse.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Boolean ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫::get_Exiting()
brtrue.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
ldsfld ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::饟ࢺ抦⭵ꔞ⠏Ћ൭୳ߘ�耽紂أ㐁몪띕�
callvirt System.Void ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫::㡹퍂〮뿈ᇹ꒿㋞䏉烔䪪曮潡曧띺ᆴ�鯐()
call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::໵薢딊㒃嫧ᛎ윦푼綐鎉헉嚉紱楩㷬㫌搢�()
ret <null>
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::큐벆橿錓結宲啭泒ウ⛒ꮫ䢊瀠ᯮᢜ;궕(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean ༺欩䜰�띋Jꋢ�䐂픂摠䪍뉎뒫䕐⎇�::쏎眅㹈톫₝珄䟰῞鹜髪�磐㮔앲䆢됓㊕폢粠()
brfalse.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Boolean 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::粪㶨Ӕ蘇垦卯륔邙擷츏䋆煳ꫥ蹵ၷ뷫䛌횥똼ᠻ()
brfalse.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Boolean ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫::get_Exiting()
brtrue.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
ldsfld ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::饟ࢺ抦⭵ꔞ⠏Ћ൭୳ߘ�耽紂أ㐁몪띕�
callvirt System.Void ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫::㡹퍂〮뿈ᇹ꒿㋞䏉烔䪪曮潡曧띺ᆴ�鯐()
call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::໵薢딊㒃嫧ᛎ윦푼綐鎉헉嚉紱楩㷬㫌搢�()
ret <null>
CnC CNCmalicious
176.huhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key Vl6roDhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port 1huhuhuhu
Host 176.huhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory Suhuhuhuhu
InstallName Clihuhuhuhu
Install 0huhuhuhu
Startup 1huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey wihuhuhuhu
HideFile 0huhuhuhu
EnableLogger 0huhuhuhu
Tag Ofhuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
176.huhuhuhu
91fc160c3a2daa73e34828f3ea380060
Port PORTmalicious
1huhuhuhu
91fc160c3a2daa73e34828f3ea380060
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙