Malicious
PE Executable
MD5: 9d9bd074b5e349b11408a63256af6d5c
Size: 514.05 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 9d9bd074b5e349b11408a63256af6d5c |
| Sha1 | ae04c23604aa238e4eb59327986d3f1ace780c90 |
| Sha256 | b54bc4caa16d8a0832ea833429556d9db8bd3b5bcf0c9cb1d0de0781bbb620d0 |
| Sha384 | e00f447cf764ad70315ed8ce2310c97444e7ebb03556712bedfe20ebbec446c2c0e7f8ff64ac7cf0ca8b0191ac05effc |
| Sha512 | 706a31584427d229a56510f448c949d5545e891510bce7943c82917e27a92c1db96c5fd7b715a591641d79a16bcdf0e80c426ec32356970ee8a9e1bd20d90681 |
| SSDeep | 6144:QTEgdc0YSXO0l6HeR9ibvgjTUQff3NMebIedNcEYjb8F94kx94i54tcTR3k:QTEgdfY8l6HifFDToY/vXwcdk |
| TLSH | 9AB47D4027F8962BE16F57B9E87114209BF5F807B2A7EB4F4540B2F92C66B069D80773 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe>pe:rsrc>bin
Shape
pe:exe>pe:rsrc>bin
malicious
3 nodes
Path
pe:exe>bin
Shape
pe:exe>bin
malicious
2 nodes
| Config. Field | Value |
|---|---|
| Conf. AES-Salt | BF-EB-huhuhuhuhuhuhuhuhuhuhu |
| Conf. AES-Key | 6EFA70huhuhuhuhuhuhuhuhuhuhu |
| Conf. AES-Salt | BF-EB-huhuhuhuhuhuhuhuhuhuhu |
| Port | 5huhuhuhu |
| Host | upxdathuhuhuhuhuhuhu |
| Conf. AES-Key | 6EFA70huhuhuhuhuhuhuhuhuhuhu |
| Version | 1huhuhuhu |
| Port | 5huhuhuhu |
| Host | upxdathuhuhuhuhuhuhu |
| ReconnectDelay | 3huhuhuhu |
| InstallName | vanghuhuhuhu |
| Install | 1huhuhuhu |
| Startup | 1huhuhuhu |
| Mutex | 4003dfhuhuhuhuhuhuhuhuhuhuhu |
| StartupKey | Rhuhuhuhu |
| HideFile | 1huhuhuhu |
| EnableLogger | 1huhuhuhu |
| Tag | Rhuhuhuhu |
| LogDirectory | Lhuhuhuhu |
| ServerSignature | Orqwj9huhuhuhuhuhuhuhuhuhuhu |
| ServerCertificate | MIIE9Dhuhuhuhuhuhuhuhuhuhuhu |
| HideLogDirectory | 1huhuhuhu |
| HideLogSubdirectory | 1huhuhuhu |
| UnattendedMod | 1huhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | Client |
| Full Name | Client |
| EntryPoint | System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::Main(System.String[]) |
| Scope Name | Client |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.4.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5.2 |
| Total Strings | 1552 |
| Main Method | System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::Main(System.String[]) |
| Main IL Instruction Count | 19 |
| Main IL | |
| Module Name | Client |
| Full Name | Client |
| EntryPoint | System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::Main(System.String[]) |
| Scope Name | Client |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Client |
| Assembly Version | 1.4.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.5.2 |
| Total Strings | 1552 |
| Main Method | System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::Main(System.String[]) |
| Main IL Instruction Count | 19 |
| Main IL | |
CnC
CNCmalicious
upxdathuhuhuhuhuhuhu
Port
PORTmalicious
5huhuhuhu
Port
PORTmalicious
5huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential