Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5: c480a5d6ea9bd6380fbc0b76462da897
Size: 77.82 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 c480a5d6ea9bd6380fbc0b76462da897
Sha1 55caaabcb37f2273c0ae2e0fa79b7b19228c5d7e
Sha256 38f215b45de95293eee5d0a4ebaf2da2341ac93bcd5b001e52bcd1b96848b96a
Sha384 feaa257b9e9f68f6fc83d3a09ae8ef8b823dc526ab17f08473002d05a3a1e7dcc25c37d38d24e6dcdaedc2327c368dd7
Sha512 3c211c8474f01c52b153fa34b874eba37649a2a1c4ce1509fd8c0b4e5265915a56bfc8ce73fd0d7c27e20ec1bfbbb7e8b99309478a3ed4969ffe6b2a6d1d5e65
SSDeep 768:xDJ6dbYT5PG1q5+nCMI0boPaVr572GxXNBSrfhRNa0GpFJ6iTBircnAGEaDDGHXV:xdH0MJaSaVr59B0uDirKAGXDGHAkMJG
TLSH B9734B087B9BD526E2BD9A7985E113450379E3533203DB5F2CC803A94F13BC79F46A9A
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Client.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Config. Field Value
Key (AES_256) MUNyZmhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature IXO65mhuhuhuhuhuhuhuhuhuhuhu
Install fhuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install-Folder %Aphuhuhuhu
Version 0.huhuhuhu
Hosts franfrhuhuhuhuhuhuhuhuhuhuhu
Ports 3huhuhuhu
Mutex Asynchuhuhuhuhuhuhu
Delay 3huhuhuhu
Group Rahuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Ragst006.exe
Full Name
Ragst006.exe
EntryPoint
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Scope Name
Ragst006.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ragst006
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
135
Main Method
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Main IL Instruction Count
3
Main IL
call System.Void hyBi4B7CHOZ0PcM2da.BrEOWILUFmZ9AtRTw7::lLHifFIsCLsZtjvFfN0i()
call System.Void Client.Program::Main()
ret <null>
Module Name
Ragst006.exe
Full Name
Ragst006.exe
EntryPoint
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Scope Name
Ragst006.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Ragst006
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
135
Main Method
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Main IL Instruction Count
3
Main IL
call System.Void hyBi4B7CHOZ0PcM2da.BrEOWILUFmZ9AtRTw7::lLHifFIsCLsZtjvFfN0i()
call System.Void Client.Program::Main()
ret <null>
Key (AES_256) MUTEXmalicious
MUNyZmhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
franfrhuhuhuhuhuhuhuhuhuhuhu
Ports PORTmalicious
3huhuhuhu
Mutex MUTEXmalicious
Asynchuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙