Malicious
Malicious

a5f2e89d8926046fb4de161c78f79b6b

PE Executable
MD5: a5f2e89d8926046fb4de161c78f79b6b
Size: 23.55 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 a5f2e89d8926046fb4de161c78f79b6b
Sha1 80324667cd1ac1f679f28e51a5954c8dae255a6b
Sha256 dc5abf20ae0c61cb9de2ca80055d369872ef9b6be35fa7ebec386e42e445d13a
Sha384 c6000452e43359db2c767a6ae1780bbf4052110d921e08cebcaade4924cded2a80f38d42a0f1dfe5646d5a0641d36f15
Sha512 62b030e41906cf27ecf420a8af30efb5337c7bb4ffb6bfdc3461c38702ce068b3774b3fc9a965f1ea7225abedb948304d646509e3120ba7ed581a969e2ef8d45
SSDeep 384:2c68yCasVKDh3OQyNpsQ1im/VjJs+PyR46vg5J++p57nhmRvR6JZlbw8hqIusZzV:0873Kt+QesGN/VjZPQRpcnus
TLSH 64B21A4E3FA98856C5AC1B74CAB5965003B491470413EE2FCDC560CBABB3AD92D4CEF9
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
malicious 1 nodes
Config. Field Value
victim_name [VN] HacKedhuhuhuhuhuhuhu
version [VR] 0huhuhuhu
executable_name [EXE] svchuhuhuhu
directory [DR] Thuhuhuhu
reg_key [RG] 90b758huhuhuhuhuhuhuhuhuhuhu
cnc_host [H] 6.tcphuhuhuhuhuhuhu
cnc_port [P] 1huhuhuhu
splitter [Y] |huhuhuhu
BD [BD] Fhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
is_user_reg [Isu] Thuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
packet_size [b] 5huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
j.exe
Full Name
j.exe
EntryPoint
System.Void j.A::main()
Scope Name
j.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
j
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
214
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
Info
PE Detect: PeReader OK (file layout)
Module Name
j.exe
Full Name
j.exe
EntryPoint
System.Void j.A::main()
Scope Name
j.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
j
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
214
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
CnC CNCmalicious
6.tcphuhuhuhuhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Config. Field Value
victim_name [VN] HacKedhuhuhuhuhuhuhu
version [VR] 0huhuhuhu
executable_name [EXE] svchuhuhuhu
directory [DR] Thuhuhuhu
reg_key [RG] 90b758huhuhuhuhuhuhuhuhuhuhu
cnc_host [H] 6.tcphuhuhuhuhuhuhu
cnc_port [P] 1huhuhuhu
splitter [Y] |huhuhuhu
BD [BD] Fhuhuhuhu
is_dir_defined [Idr] Fhuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
is_user_reg [Isu] Thuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
packet_size [b] 5huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
6.tcphuhuhuhuhuhuhu
a5f2e89d8926046fb4de161c78f79b6b
Port PORTmalicious
1huhuhuhu
a5f2e89d8926046fb4de161c78f79b6b
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙