Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5:
Size: 0 B
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
PeID
Microsoft Visual C# / Basic .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key 9yQgPchuhuhuhuhuhuhu
Version 1.huhuhuhu
Port alexihuhuhuhuhuhuhu
Host alexihuhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory Suhuhuhuhu
InstallName Clihuhuhuhu
Install 0huhuhuhu
Startup 1huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey Cliehuhuhuhuhuhuhu
HideFile 0huhuhuhu
EnableLogger 1huhuhuhu
Tag rhuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::䩞幓⩻邘哈쨥蚛ꎐ쓝䊃蓌굪謬琺逋⯝峞쓏(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean 놾奩層ꘜ爐덲脎ᙧ鍜Ჿ湕퍕ˣڝ輑�櫺ɰ::햭ᄚ麥䊛㫨ࠍﹴ鋃㏠뤆晬䒵᭠ᵒꦤ௜ዮㅒ()
brfalse.s IL_0040: call System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::嚃몆琐䴦胩啴鳙꣛﵊娬Ƭ✑寝ꮖ뭽㓕Ⴤ()
call System.Boolean ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::蹙꒳蔗独鍆핝㵺ဪ⣰ꬫ丷黬ፑ�寥睞⚉()
brfalse.s IL_0040: call System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::嚃몆琐䴦胩啴鳙꣛﵊娬Ƭ✑寝ꮖ뭽㓕Ⴤ()
call System.Boolean 햙훉ㄑ뷬૎룕釆軫꾆셜㵳∻뵎૴蘀췦悴唡咾ꆭ::get_Exiting()
brtrue.s IL_0040: call System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::嚃몆琐䴦胩啴鳙꣛﵊娬Ƭ✑寝ꮖ뭽㓕Ⴤ()
ldsfld 햙훉ㄑ뷬૎룕釆軫꾆셜㵳∻뵎૴蘀췦悴唡咾ꆭ ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::慞낞䫲釕谎赕㕆쯵勧늍렘ŧ蜤謃䂵헙и釈
callvirt System.Void 햙훉ㄑ뷬૎룕釆軫꾆셜㵳∻뵎૴蘀췦悴唡咾ꆭ::䇇༎했폓沆悽〙㮊詇顣꿚呇薐ᒹ⡹墪䤒븇㰭()
call System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::嚃몆琐䴦胩啴鳙꣛﵊娬Ƭ✑寝ꮖ뭽㓕Ⴤ()
call System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::�몓킐皔㒀핂砺푿識ு쐡㿘鈒㐿踔㿾મ➠()
ret <null>
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::䩞幓⩻邘哈쨥蚛ꎐ쓝䊃蓌굪謬琺逋⯝峞쓏(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean 놾奩層ꘜ爐덲脎ᙧ鍜Ჿ湕퍕ˣڝ輑�櫺ɰ::햭ᄚ麥䊛㫨ࠍﹴ鋃㏠뤆晬䒵᭠ᵒꦤ௜ዮㅒ()
brfalse.s IL_0040: call System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::嚃몆琐䴦胩啴鳙꣛﵊娬Ƭ✑寝ꮖ뭽㓕Ⴤ()
call System.Boolean ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::蹙꒳蔗独鍆핝㵺ဪ⣰ꬫ丷黬ፑ�寥睞⚉()
brfalse.s IL_0040: call System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::嚃몆琐䴦胩啴鳙꣛﵊娬Ƭ✑寝ꮖ뭽㓕Ⴤ()
call System.Boolean 햙훉ㄑ뷬૎룕釆軫꾆셜㵳∻뵎૴蘀췦悴唡咾ꆭ::get_Exiting()
brtrue.s IL_0040: call System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::嚃몆琐䴦胩啴鳙꣛﵊娬Ƭ✑寝ꮖ뭽㓕Ⴤ()
ldsfld 햙훉ㄑ뷬૎룕釆軫꾆셜㵳∻뵎૴蘀췦悴唡咾ꆭ ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::慞낞䫲釕谎赕㕆쯵勧늍렘ŧ蜤謃䂵헙и釈
callvirt System.Void 햙훉ㄑ뷬૎룕釆軫꾆셜㵳∻뵎૴蘀췦悴唡咾ꆭ::䇇༎했폓沆悽〙㮊詇顣꿚呇薐ᒹ⡹墪䤒븇㰭()
call System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::嚃몆琐䴦胩啴鳙꣛﵊娬Ƭ✑寝ꮖ뭽㓕Ⴤ()
call System.Void ⇮幸肣�⻅ထ꿷䏢ሺ뙣䜞琢均擫ﻅ❇맡::�몓킐皔㒀핂砺푿識ு쐡㿘鈒㐿踔㿾મ➠()
ret <null>
CnC CNCmalicious
alexihuhuhuhuhuhuhu
Port PORTmalicious
alexihuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙