Malicious
Malicious

PE Executable
MD5: b0d26bd4ee5d3999407c0cdba17c255c
Size: 376.84 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 b0d26bd4ee5d3999407c0cdba17c255c
Sha1 9926ab71e9b5acda4a1f3c70781cdf2533e60a16
Sha256 8a5bee9f9a6511fcfef7bbdc1aa252c3f13894fff1296a6679b6e32d3df272d6
Sha384 cabc99ee641e3679ca47ffa6b6bc783a19a95df27e5a1cad943083042c91d6f7cd55dc9ad3a421e5ffa845a838c0dcdb
Sha512 d33eb0a10e49359df014122aae4306f530960842e5ccfb5c897ab0bab86fb4fbf63fbd33235643af61464fa0b09196461c992ba8f8471af2b583e34cece7dbb0
SSDeep 6144:qN6bPXhLApfph5BS6kgOmbmOjMfeouxPYBNF0LsfOY+:imhApzS6k3JgMfeoaPYfOLsfOY+
TLSH A9849D1337A4EE3BD1FE1736E43206090BB0D4677616E38B5A6A55B92D133868E913F3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key Vl6roDhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port 1huhuhuhu
Host 176.huhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory Suhuhuhuhu
InstallName Clihuhuhuhu
Install 0huhuhuhu
Startup 1huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey wihuhuhuhu
HideFile 0huhuhuhu
EnableLogger 0huhuhuhu
Tag Ofhuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader FAIL, AsmResolver Mapped OK
Info
Remap: Mapped -> FileLayout (RAM only) as [Rebuild from dump]_07ab9e2b.exe
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::큐벆橿錓結宲啭泒ウ⛒ꮫ䢊瀠ᯮᢜ;궕(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean ༺欩䜰�띋Jꋢ�䐂픂摠䪍뉎뒫䕐⎇�::쏎眅㹈톫₝珄䟰῞鹜髪�磐㮔앲䆢됓㊕폢粠()
brfalse.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Boolean 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::粪㶨Ӕ蘇垦卯륔邙擷츏䋆煳ꫥ蹵ၷ뷫䛌횥똼ᠻ()
brfalse.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Boolean ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫::get_Exiting()
brtrue.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
ldsfld ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::饟ࢺ抦⭵ꔞ⠏Ћ൭୳ߘ�耽紂أ㐁몪띕�
callvirt System.Void ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫::㡹퍂〮뿈ᇹ꒿㋞䏉烔䪪曮潡曧띺ᆴ�鯐()
call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::໵薢딊㒃嫧ᛎ윦푼綐鎉헉嚉紱楩㷬㫌搢�()
ret <null>
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::큐벆橿錓結宲啭泒ウ⛒ꮫ䢊瀠ᯮᢜ;궕(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean ༺欩䜰�띋Jꋢ�䐂픂摠䪍뉎뒫䕐⎇�::쏎眅㹈톫₝珄䟰῞鹜髪�磐㮔앲䆢됓㊕폢粠()
brfalse.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Boolean 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::粪㶨Ӕ蘇垦卯륔邙擷츏䋆煳ꫥ蹵ၷ뷫䛌횥똼ᠻ()
brfalse.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Boolean ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫::get_Exiting()
brtrue.s IL_0040: call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
ldsfld ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::饟ࢺ抦⭵ꔞ⠏Ћ൭୳ߘ�耽紂أ㐁몪띕�
callvirt System.Void ᚖ펒봱晴⊟瞧༢짌ꊓ��텴⭛䢛뎢턑ڃ蛋㰫::㡹퍂〮뿈ᇹ꒿㋞䏉烔䪪曮潡曧띺ᆴ�鯐()
call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::උ冷튅༔ꍈ⥪漑຃Ⰱ訬坿Έ싱짂㧱낧㵡̎()
call System.Void 뻊墿əꜢ敮먢큍ﱤꂋ棲镘ᯣኟὬ귑ᷕ::໵薢딊㒃嫧ᛎ윦푼綐鎉헉嚉紱楩㷬㫌搢�()
ret <null>
CnC CNCmalicious
176.huhuhuhu
Port PORTmalicious
1huhuhuhu
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
176.huhuhuhu
Port PORTmalicious
1huhuhuhu
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key Vl6roDhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port 1huhuhuhu
Host 176.huhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory Suhuhuhuhu
InstallName Clihuhuhuhu
Install 0huhuhuhu
Startup 1huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey wihuhuhuhu
HideFile 0huhuhuhu
EnableLogger 0huhuhuhu
Tag Ofhuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
176.huhuhuhu
b0d26bd4ee5d3999407c0cdba17c255c
Port PORTmalicious
1huhuhuhu
b0d26bd4ee5d3999407c0cdba17c255c
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
b0d26bd4ee5d3999407c0cdba17c255c
CnC CNCmalicious
176.huhuhuhu
b0d26bd4ee5d3999407c0cdba17c255c › [Rebuild from dump]_07ab9e2b.exe
Port PORTmalicious
1huhuhuhu
b0d26bd4ee5d3999407c0cdba17c255c › [Rebuild from dump]_07ab9e2b.exe
PE Layout UNKNWOWNsuspect
Memoryhuhuhuhuhuhuhuhuhuhuhu
b0d26bd4ee5d3999407c0cdba17c255c › [Rebuild from dump]_07ab9e2b.exe
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙