Malicious
Malicious

9d9bd074b5e349b11408a63256af6d5c

Share on LinkedIn
Print
PE Executable
MD5: 9d9bd074b5e349b11408a63256af6d5c
Size: 514.05 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 9d9bd074b5e349b11408a63256af6d5c
Sha1 ae04c23604aa238e4eb59327986d3f1ace780c90
Sha256 b54bc4caa16d8a0832ea833429556d9db8bd3b5bcf0c9cb1d0de0781bbb620d0
Sha384 e00f447cf764ad70315ed8ce2310c97444e7ebb03556712bedfe20ebbec446c2c0e7f8ff64ac7cf0ca8b0191ac05effc
Sha512 706a31584427d229a56510f448c949d5545e891510bce7943c82917e27a92c1db96c5fd7b715a591641d79a16bcdf0e80c426ec32356970ee8a9e1bd20d90681
SSDeep 6144:QTEgdc0YSXO0l6HeR9ibvgjTUQff3NMebIedNcEYjb8F94kx94i54tcTR3k:QTEgdfY8l6HifFDToY/vXwcdk
TLSH 9AB47D4027F8962BE16F57B9E87114209BF5F807B2A7EB4F4540B2F92C66B069D80773
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Quasar.Client.Properties.Resources.resources
ILRepack.List
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key 6EFA70huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port 5huhuhuhu
Host upxdathuhuhuhuhuhuhu
Conf. AES-Key 6EFA70huhuhuhuhuhuhuhuhuhuhu
Version 1huhuhuhu
Port 5huhuhuhu
Host upxdathuhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
InstallName vanghuhuhuhu
Install 1huhuhuhu
Startup 1huhuhuhu
Mutex 4003dfhuhuhuhuhuhuhuhuhuhuhu
StartupKey Rhuhuhuhu
HideFile 1huhuhuhu
EnableLogger 1huhuhuhu
Tag Rhuhuhuhu
LogDirectory Lhuhuhuhu
ServerSignature Orqwj9huhuhuhuhuhuhuhuhuhuhu
ServerCertificate MIIE9Dhuhuhuhuhuhuhuhuhuhuhu
HideLogDirectory 1huhuhuhu
HideLogSubdirectory 1huhuhuhu
UnattendedMod 1huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client
Full Name
Client
EntryPoint
System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
1552
Main Method
System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::놵惌柍篦꽅㏔敫䌕礈ຸᐟ㜜琢鰧曣彀ۇ(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::욶ቧ寍ྞⵧ劦武䓔霥㘰濜莖䅺㑰ஶ�쒥噞଩顗(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 鵚㊿鄧❩劀만㻍ꗆ彡琰貸쵠┳㹞귈琕鋦䏍脏::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
Client
Full Name
Client
EntryPoint
System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::Main(System.String[])
Scope Name
Client
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.4.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5.2
Total Strings
1552
Main Method
System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::Main(System.String[])
Main IL Instruction Count
19
Main IL
ldc.i4 3072
call System.Void System.Net.ServicePointManager::set_SecurityProtocol(System.Net.SecurityProtocolType)
ldc.i4.2 <null>
call System.Void System.Windows.Forms.Application::SetUnhandledExceptionMode(System.Windows.Forms.UnhandledExceptionMode)
ldnull <null>
ldftn System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::놵惌柍篦꽅㏔敫䌕礈ຸᐟ㜜琢鰧曣彀ۇ(System.Object,System.Threading.ThreadExceptionEventArgs)
newobj System.Void System.Threading.ThreadExceptionEventHandler::.ctor(System.Object,System.IntPtr)
call System.Void System.Windows.Forms.Application::add_ThreadException(System.Threading.ThreadExceptionEventHandler)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 脫橧닶閞逤슢场袼먚ﰹ痘뼓ଌ⯡䪶Ꞧ::욶ቧ寍ྞⵧ劦武䓔霥㘰濜莖䅺㑰ஶ�쒥噞଩顗(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void 鵚㊿鄧❩劀만㻍ꗆ彡琰貸쵠┳㹞귈琕鋦䏍脏::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
CnC CNCmalicious
upxdathuhuhuhuhuhuhu
Port PORTmalicious
5huhuhuhu
Port PORTmalicious
5huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙