Malicious
Malicious

c4911b45ca4bfeee9cb940cc2b8696c3

PE Executable
MD5: c4911b45ca4bfeee9cb940cc2b8696c3
Size: 48.64 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 c4911b45ca4bfeee9cb940cc2b8696c3
Sha1 1f53ed19e8941ea62fcac94854dc669f210942c4
Sha256 72b2cd81acb88e14d1f0a3cb660e48a78deaecac9135f762b838cd41fbc8c6fc
Sha384 3429a9f64b9a2c39077b6ffb4fabc82e70d66d784fb540d8ca642a0289164f1afa8bb46e8a89fd7668e9521ec7d7764d
Sha512 93cf83cc489ae2190bd2e34646ea3f90f5116285c34928d48eb1d44c4d09a33f5a018545c6defc1d0ec5a4742f998921df575214b99b72f835125151a25615b8
SSDeep 768:0uYHKTsufqG9vSLjWUvlPRmo2qbgo6+TsH11YWPI2Y0bg5OogVy4VpO9cOnYVBDo:0uYHKTsjMvSX246+U1Q2Tbg59I89Y7dO
TLSH 84233B0037E8816BF2BE5F78ACF22245857BE6673603D54D2CC452D75623BC29A426FE
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) MFJRSWhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature SReTqHhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS thuhuhuhu
Anti-VM thuhuhuhu
Install File Chromhuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts tg8huhuhuhu
Ports 4huhuhuhu
Mutex rDZfhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group tg8huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
ITUBIybJuYIU
Full Name
ITUBIybJuYIU
EntryPoint
System.Void pitifUYUNHjlB.NyfHEzItuWVzeL::Main()
Scope Name
ITUBIybJuYIU
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tgteru
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void pitifUYUNHjlB.NyfHEzItuWVzeL::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::EDBoplIyrkV
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean pitifUYUNHjlB.fzKtrGeJnQGT::tXbvpsAtmfpeTa()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean BUVXqSMDKkYO.TtYaCUDqZWpc::fdoMYfWKMEhnk()
brtrue IL_0043: ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::zlDRZVpWYKTk
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::zlDRZVpWYKTk
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::bXlOpHnUuPsG
call System.Void BUVXqSMDKkYO.qCXVoavqMgCdf::JDDIukqMVSA()
ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::bXlOpHnUuPsG
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::LeFRZiizGYAc
call System.Void XNJvcoWPDg.PITGRyWIDyoDEAc::SBVCzidPhWoFqVS()
ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::LeFRZiizGYAc
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void BUVXqSMDKkYO.GywdbvOxjTeG::VchtQKCVhvpksng()
call System.Boolean BUVXqSMDKkYO.GywdbvOxjTeG::cOlTJhNyipp()
brfalse IL_0089: call System.Void BUVXqSMDKkYO.GywdbvOxjTeG::VchtQKCVhvpksng()
call System.Void BUVXqSMDKkYO.kGLTPCGLFE::ojtLQAUMrTuDU()
call System.Void BUVXqSMDKkYO.GywdbvOxjTeG::VchtQKCVhvpksng()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean wcwDkORKlqbRfvS.UrFLrHbcwBJV::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void wcwDkORKlqbRfvS.UrFLrHbcwBJV::XPjPDVzSSrI()
call System.Void wcwDkORKlqbRfvS.UrFLrHbcwBJV::aAoopscrYYA()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
ITUBIybJuYIU
Full Name
ITUBIybJuYIU
EntryPoint
System.Void pitifUYUNHjlB.NyfHEzItuWVzeL::Main()
Scope Name
ITUBIybJuYIU
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tgteru
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void pitifUYUNHjlB.NyfHEzItuWVzeL::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::EDBoplIyrkV
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean pitifUYUNHjlB.fzKtrGeJnQGT::tXbvpsAtmfpeTa()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean BUVXqSMDKkYO.TtYaCUDqZWpc::fdoMYfWKMEhnk()
brtrue IL_0043: ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::zlDRZVpWYKTk
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::zlDRZVpWYKTk
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::bXlOpHnUuPsG
call System.Void BUVXqSMDKkYO.qCXVoavqMgCdf::JDDIukqMVSA()
ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::bXlOpHnUuPsG
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::LeFRZiizGYAc
call System.Void XNJvcoWPDg.PITGRyWIDyoDEAc::SBVCzidPhWoFqVS()
ldsfld System.String pitifUYUNHjlB.fzKtrGeJnQGT::LeFRZiizGYAc
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void BUVXqSMDKkYO.GywdbvOxjTeG::VchtQKCVhvpksng()
call System.Boolean BUVXqSMDKkYO.GywdbvOxjTeG::cOlTJhNyipp()
brfalse IL_0089: call System.Void BUVXqSMDKkYO.GywdbvOxjTeG::VchtQKCVhvpksng()
call System.Void BUVXqSMDKkYO.kGLTPCGLFE::ojtLQAUMrTuDU()
call System.Void BUVXqSMDKkYO.GywdbvOxjTeG::VchtQKCVhvpksng()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean wcwDkORKlqbRfvS.UrFLrHbcwBJV::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void wcwDkORKlqbRfvS.UrFLrHbcwBJV::XPjPDVzSSrI()
call System.Void wcwDkORKlqbRfvS.UrFLrHbcwBJV::aAoopscrYYA()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Key (AES_256) MUTEXmalicious
MFJRSWhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
tg8huhuhuhu
Ports PORTmalicious
4huhuhuhu
Mutex MUTEXmalicious
rDZfhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Key (AES_256) MFJRSWhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature SReTqHhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS thuhuhuhu
Anti-VM thuhuhuhu
Install File Chromhuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts tg8huhuhuhu
Ports 4huhuhuhu
Mutex rDZfhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group tg8huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Key (AES_256) MUTEXmalicious
MFJRSWhuhuhuhuhuhuhuhuhuhuhu
c4911b45ca4bfeee9cb940cc2b8696c3
CnC CNCmalicious
tg8huhuhuhu
c4911b45ca4bfeee9cb940cc2b8696c3
Ports PORTmalicious
4huhuhuhu
c4911b45ca4bfeee9cb940cc2b8696c3
Mutex MUTEXmalicious
rDZfhuhuhuhu
c4911b45ca4bfeee9cb940cc2b8696c3
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙