Malicious
Malicious

9f70650b217f11adaed79d1b31272da5

Share on LinkedIn
Print
PE Executable
MD5: 9f70650b217f11adaed79d1b31272da5
Size: 56.83 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 9f70650b217f11adaed79d1b31272da5
Sha1 e3ecabfbd824a22f7df8b6ca6bd0f75ec057fee2
Sha256 5e4f37340fb9e84476518e9fb450815c8135ba471f11168a3b7d4a8fc32f25c3
Sha384 fa0737dd3dbdee25eacfba372edce93e553825bf1c09eb72f1b1ff40620b0fa926501ba5eb0ef4fa37cc21693799f47e
Sha512 d12a6e756918700b54781b86d2d025e514b235a66fe3ffcc170e09f74223beb764cc2ec8cc2849b722e40b6a66f8940071b76ff167e47a16ed33092e0173e1a0
SSDeep 1536:xDfzFI9di8rvASatIUYaUb3sd+hGTkeSV7pHx:NzeESaeUTUb30+hGTW7Zx
TLSH 20432A0437FC8127F5BE5F7898F261464776A7236913DA8E2CD411CB0A23BC59A427EE
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) V2RibEhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature lhssTAhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install File tele@ehuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts kolaybhuhuhuhuhuhuhuhuhuhuhu
Ports 44huhuhuhu
Mutex z9m0huhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group Dehuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
Program.exe
Full Name
Program.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
Program.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Program
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
227
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
64
Main IL
ldc.i4.0 <null>
stloc.0 <null>
ldsfld System.String Client.Settings::Delay
ldloca.s V_0
call System.Boolean System.Int32::TryParse(System.String,System.Int32&)
brtrue IL_0015: ldc.i4.0
ldc.i4.0 <null>
stloc.0 <null>
ldc.i4.0 <null>
stloc.1 <null>
br IL_002A: ldloc.1
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.1 <null>
ldc.i4.1 <null>
add <null>
stloc.1 <null>
ldloc.1 <null>
ldloc.0 <null>
blt.s IL_001C: ldc.i4 1000
leave IL_0039: call System.Boolean Client.Settings::InitializeSettings()
pop <null>
leave IL_0039: call System.Boolean Client.Settings::InitializeSettings()
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0053: call System.Threading.Tasks.Task Client.Program::SendRequests()
ldstr Settings initialization failed. Exiting.
call System.Void System.Console::WriteLine(System.String)
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Threading.Tasks.Task Client.Program::SendRequests()
pop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0069: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_007D: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0091: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00AF: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_00AF: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
leave IL_00BF: nop
pop <null>
leave IL_00BF: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00D4: leave IL_00DF
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_00DF: ldc.i4 5000
pop <null>
leave IL_00DF: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_00BF: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
Program.exe
Full Name
Program.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
Program.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Program
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
227
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
64
Main IL
ldc.i4.0 <null>
stloc.0 <null>
ldsfld System.String Client.Settings::Delay
ldloca.s V_0
call System.Boolean System.Int32::TryParse(System.String,System.Int32&)
brtrue IL_0015: ldc.i4.0
ldc.i4.0 <null>
stloc.0 <null>
ldc.i4.0 <null>
stloc.1 <null>
br IL_002A: ldloc.1
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.1 <null>
ldc.i4.1 <null>
add <null>
stloc.1 <null>
ldloc.1 <null>
ldloc.0 <null>
blt.s IL_001C: ldc.i4 1000
leave IL_0039: call System.Boolean Client.Settings::InitializeSettings()
pop <null>
leave IL_0039: call System.Boolean Client.Settings::InitializeSettings()
call System.Boolean Client.Settings::InitializeSettings()
brtrue IL_0053: call System.Threading.Tasks.Task Client.Program::SendRequests()
ldstr Settings initialization failed. Exiting.
call System.Void System.Console::WriteLine(System.String)
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Threading.Tasks.Task Client.Program::SendRequests()
pop <null>
call System.Boolean Client.Helper.MutexControl::CreateMutex()
brtrue IL_0069: ldsfld System.String Client.Settings::Anti
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String Client.Settings::Anti
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_007D: ldsfld System.String Client.Settings::Install
call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis()
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0091: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_00AF: call System.Void Client.Helper.Methods::PreventSleep()
call System.Boolean Client.Helper.Methods::IsAdmin()
brfalse IL_00AF: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
call System.Void Client.Helper.Methods::PreventSleep()
leave IL_00BF: nop
pop <null>
leave IL_00BF: nop
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
brtrue IL_00D4: leave IL_00DF
call System.Void Client.Connection.ClientSocket::Reconnect()
call System.Void Client.Connection.ClientSocket::InitializeClient()
leave IL_00DF: ldc.i4 5000
pop <null>
leave IL_00DF: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_00BF: nop
Key (AES_256) MUTEXmalicious
V2RibEhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
kolahuhuhuhuhuhuhu
CnC CNCmalicious
c2.kohuhuhuhuhuhuhu
Ports PORTmalicious
4huhuhuhu
Ports PORTmalicious
8huhuhuhu
Mutex MUTEXmalicious
z9m0huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙