Malicious
Malicious

bb44a39a862c20e9e0909f1c993a81ee

PE Executable
MD5: bb44a39a862c20e9e0909f1c993a81ee
Size: 33.28 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 bb44a39a862c20e9e0909f1c993a81ee
Sha1 81cc63b18e89590d1a0ff5b5bf2ac3a0f800a185
Sha256 cc4f4e1466183b11cfda923915e34cfd338cbf87a656d911120ceb784846d334
Sha384 b234457ef2d536803a3569a49344ec953d4a44e19a324ed55896256f8d6f85d12f6b1b407651430a2d3d80217acebdc4
Sha512 07c6af35234afe78590cca8efda448079139c884015d8adae472b765bbca08fe5c6b38a0f14b905890308f7f7c0f02367aca213d0cacd60a42f5408da5cb411a
SSDeep 384:vlRmhGD91SluSWhnHHxzLmYV3Tm2eaFO4FzRApkFTBLTsOZwpGd2v99IkuismVF/:tRPD9OQhx/BV3Tw49FzVFE9jnOjhibv
TLSH 57E22B4877E44712DAFEAFB12DF261061670D51BD813EF9E0CE485EA2B67AC047407E6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Mutex Phzvshuhuhuhuhuhuhu
Hosts throughuhuhuhuhuhuhuhuhuhuhu
Port 2huhuhuhu
KEY <12huhuhuhu
USBNM <Xwhuhuhuhu
family xhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
XClient.exe
Full Name
XClient.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
XClient.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XClient
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
156
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
58
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::Hosts
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Hosts
ldsfld System.String Settings::Port
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Port
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00AB: call System.Void Stub.Helper::PreventSleep()
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.0 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldloc.0 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Module Name
XClient.exe
Full Name
XClient.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
XClient.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XClient
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
156
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
58
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::Hosts
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Hosts
ldsfld System.String Settings::Port
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Port
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00AB: call System.Void Stub.Helper::PreventSleep()
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.0 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldloc.0 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Mutex MUTEXmalicious
Phzvshuhuhuhuhuhuhu
CnC CNCmalicious
throughuhuhuhuhuhuhuhuhuhuhu
Port PORTmalicious
2huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Mutex Phzvshuhuhuhuhuhuhu
Hosts throughuhuhuhuhuhuhuhuhuhuhu
Port 2huhuhuhu
KEY <12huhuhuhu
USBNM <Xwhuhuhuhu
family xhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Mutex MUTEXmalicious
Phzvshuhuhuhuhuhuhu
bb44a39a862c20e9e0909f1c993a81ee
CnC CNCmalicious
throughuhuhuhuhuhuhuhuhuhuhu
bb44a39a862c20e9e0909f1c993a81ee
Port PORTmalicious
2huhuhuhu
bb44a39a862c20e9e0909f1c993a81ee
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙