Malicious
PE Executable
MD5: a5f2e89d8926046fb4de161c78f79b6b
Size: 23.55 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | a5f2e89d8926046fb4de161c78f79b6b |
| Sha1 | 80324667cd1ac1f679f28e51a5954c8dae255a6b |
| Sha256 | dc5abf20ae0c61cb9de2ca80055d369872ef9b6be35fa7ebec386e42e445d13a |
| Sha384 | c6000452e43359db2c767a6ae1780bbf4052110d921e08cebcaade4924cded2a80f38d42a0f1dfe5646d5a0641d36f15 |
| Sha512 | 62b030e41906cf27ecf420a8af30efb5337c7bb4ffb6bfdc3461c38702ce068b3774b3fc9a965f1ea7225abedb948304d646509e3120ba7ed581a969e2ef8d45 |
| SSDeep | 384:2c68yCasVKDh3OQyNpsQ1im/VjJs+PyR46vg5J++p57nhmRvR6JZlbw8hqIusZzV:0873Kt+QesGN/VjZPQRpcnus |
| TLSH | 64B21A4E3FA98856C5AC1B74CAB5965003B491470413EE2FCDC560CBABB3AD92D4CEF9 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe
Shape
pe:exe
malicious
1 nodes
| Config. Field | Value |
|---|---|
| victim_name [VN] | HacKedhuhuhuhuhuhuhu |
| version [VR] | 0huhuhuhu |
| executable_name [EXE] | svchuhuhuhu |
| directory [DR] | Thuhuhuhu |
| reg_key [RG] | 90b758huhuhuhuhuhuhuhuhuhuhu |
| cnc_host [H] | 6.tcphuhuhuhuhuhuhu |
| cnc_port [P] | 1huhuhuhu |
| splitter [Y] | |huhuhuhu |
| BD [BD] | Fhuhuhuhu |
| is_dir_defined [Idr] | Fhuhuhuhu |
| is_startup_folder [IsF] | Thuhuhuhu |
| is_user_reg [Isu] | Thuhuhuhu |
| reg_path [sf] | Softwahuhuhuhuhuhuhuhuhuhuhu |
| packet_size [b] | 5huhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Module Name | j.exe |
| Full Name | j.exe |
| EntryPoint | System.Void j.A::main() |
| Scope Name | j.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | j |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 214 |
| Main Method | System.Void j.A::main() |
| Main IL Instruction Count | 2 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | j.exe |
| Full Name | j.exe |
| EntryPoint | System.Void j.A::main() |
| Scope Name | j.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v2.0.50727 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | j |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 214 |
| Main Method | System.Void j.A::main() |
| Main IL Instruction Count | 2 |
| Main IL | |
CnC
CNCmalicious
6.tcphuhuhuhuhuhuhu
Port
PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential