Malicious
Malicious

9722555e8540d9654202860707eead13

PE Executable
MD5: 9722555e8540d9654202860707eead13
Size: 46.08 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 9722555e8540d9654202860707eead13
Sha1 71656c57dcc146118993b95b7f909acc750ae77b
Sha256 17afd744670767b97cb63ee1490d9160cce77240ea69fd9984f61da67bee6b26
Sha384 12f108f97d19e933bb2b1fe19b926422e66a7d1e8b0a8192b39be2a50f2e6cefcdc8e03386ee195cd9bc60fb2ee179d3
Sha512 96d2f1e7e73e8b832e5dd0e597079cfe8f0f05ca516be03c0d564e27d52d1cd32b6aa3bbc85b43f446da18ca5dd90c47c3bd0cbbe1199cdc5529ce69e777554b
SSDeep 768:Buny5TgoqzqWU8d9rmo2qrqisHkDFIKPINnjbUgX3i3TCDpO3SezdBDZ3x:Buny5TgNR2osW+zNjb7XS3W0Se3d3x
TLSH 31231A003BE9822BF2BE4F78ACF26145467BF1672603D9491CC441DB5713BC69642AFE
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) Mzh0dlhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature Chf5q+huhuhuhuhuhuhuhuhuhuhu
Install fhuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts pw.sonhuhuhuhuhuhuhuhuhuhuhu
Ports 80,88,huhuhuhuhuhuhu
Mutex ZxR3huhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group Dehuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
DNS_Async.exe
Full Name
DNS_Async.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
DNS_Async.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DNS_Async
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0043: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
DNS_Async.exe
Full Name
DNS_Async.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
DNS_Async.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
DNS_Async
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String Client.Settings::Delay
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0043: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_0089: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Key (AES_256) MUTEXmalicious
Mzh0dlhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
pw.sohuhuhuhuhuhuhu
CnC CNCmalicious
ds.khuhuhuhuhuhuhu
Ports PORTmalicious
8huhuhuhu
Ports PORTmalicious
8huhuhuhu
Ports PORTmalicious
1huhuhuhu
Ports PORTmalicious
4huhuhuhu
Ports PORTmalicious
9huhuhuhu
Ports PORTmalicious
8huhuhuhu
Mutex MUTEXmalicious
ZxR3huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Key (AES_256) Mzh0dlhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature Chf5q+huhuhuhuhuhuhuhuhuhuhu
Install fhuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts pw.sonhuhuhuhuhuhuhuhuhuhuhu
Ports 80,88,huhuhuhuhuhuhu
Mutex ZxR3huhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group Dehuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Key (AES_256) MUTEXmalicious
Mzh0dlhuhuhuhuhuhuhuhuhuhuhu
9722555e8540d9654202860707eead13
CnC CNCmalicious
pw.sohuhuhuhuhuhuhu
9722555e8540d9654202860707eead13
CnC CNCmalicious
ds.khuhuhuhuhuhuhu
9722555e8540d9654202860707eead13
Ports PORTmalicious
8huhuhuhu
9722555e8540d9654202860707eead13
Ports PORTmalicious
8huhuhuhu
9722555e8540d9654202860707eead13
Ports PORTmalicious
1huhuhuhu
9722555e8540d9654202860707eead13
Ports PORTmalicious
4huhuhuhu
9722555e8540d9654202860707eead13
Ports PORTmalicious
9huhuhuhu
9722555e8540d9654202860707eead13
Ports PORTmalicious
8huhuhuhu
9722555e8540d9654202860707eead13
Mutex MUTEXmalicious
ZxR3huhuhuhu
9722555e8540d9654202860707eead13
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙