Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key ZHHBiAhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port
Host 185.2huhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory Suhuhuhuhu
InstallName Clihuhuhuhu
Install 1huhuhuhu
Startup 0huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey Quasahuhuhuhuhuhuhu
HideFile 0huhuhuhu
EnableLogger 1huhuhuhu
Tag Ofhuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::慎짉வ�漂똚훸Ṓ꒏嬧矦竅蓻闹灎듃鹈鎫ꔵ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean �䣾既聑눬豘떍躶荪ো覢::᱁䕱ƽ䢖⅝孩큓㷡萹㵐덺偡ꦦᷙ眂诒쾉()
brfalse.s IL_0040: call System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::憽갍淴�൸䝩榎⥕ヅ㙭⛵ⳛ䜩詟矣὇滴壛覮()
call System.Boolean 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::ꙏ뢸ງ쨗윎訠﵏䧆됴엜玧თ프審陖旵䍫㷹捂슀()
brfalse.s IL_0040: call System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::憽갍淴�൸䝩榎⥕ヅ㙭⛵ⳛ䜩詟矣὇滴壛覮()
call System.Boolean 솏雗킃Ⰶ浐嵽⧟�ʼ嚫ᛏ훲藪::get_Exiting()
brtrue.s IL_0040: call System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::憽갍淴�൸䝩榎⥕ヅ㙭⛵ⳛ䜩詟矣὇滴壛覮()
ldsfld 솏雗킃Ⰶ浐嵽⧟�ʼ嚫ᛏ훲藪 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::泝ꉤ⭴꾛윓ᩒ�ഓ粵䒫䀩⠂㯼埠䂵➒鑸䟉
callvirt System.Void 솏雗킃Ⰶ浐嵽⧟�ʼ嚫ᛏ훲藪::�딨�虎嚰虸祎끪莈Ḻḍ₿焸ᵦ싵()
call System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::憽갍淴�൸䝩榎⥕ヅ㙭⛵ⳛ䜩詟矣὇滴壛覮()
call System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::ㅚ澗糵〞䯀航ꭻ嶷鞑迀嵓ਡ栫册䧽()
ret <null>
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::慎짉வ�漂똚훸Ṓ꒏嬧矦竅蓻闹灎듃鹈鎫ꔵ(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean �䣾既聑눬豘떍躶荪ো覢::᱁䕱ƽ䢖⅝孩큓㷡萹㵐덺偡ꦦᷙ眂诒쾉()
brfalse.s IL_0040: call System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::憽갍淴�൸䝩榎⥕ヅ㙭⛵ⳛ䜩詟矣὇滴壛覮()
call System.Boolean 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::ꙏ뢸ງ쨗윎訠﵏䧆됴엜玧თ프審陖旵䍫㷹捂슀()
brfalse.s IL_0040: call System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::憽갍淴�൸䝩榎⥕ヅ㙭⛵ⳛ䜩詟矣὇滴壛覮()
call System.Boolean 솏雗킃Ⰶ浐嵽⧟�ʼ嚫ᛏ훲藪::get_Exiting()
brtrue.s IL_0040: call System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::憽갍淴�൸䝩榎⥕ヅ㙭⛵ⳛ䜩詟矣὇滴壛覮()
ldsfld 솏雗킃Ⰶ浐嵽⧟�ʼ嚫ᛏ훲藪 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::泝ꉤ⭴꾛윓ᩒ�ഓ粵䒫䀩⠂㯼埠䂵➒鑸䟉
callvirt System.Void 솏雗킃Ⰶ浐嵽⧟�ʼ嚫ᛏ훲藪::�딨�虎嚰虸祎끪莈Ḻḍ₿焸ᵦ싵()
call System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::憽갍淴�൸䝩榎⥕ヅ㙭⛵ⳛ䜩詟矣὇滴壛覮()
call System.Void 㑶ȡ䆕숇䠕✓뜶猕䲤쓛ꑑ懮퓹璖ﭘ奣뀭㎊ᔙ匰::ㅚ澗糵〞䯀航ꭻ嶷鞑迀嵓ਡ栫册䧽()
ret <null>
CnC CNCmalicious
185.2huhuhuhuhuhuhu
Port PORTmalicious
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙