Suspicious
Suspect

c5c6ccefaec1268d1e02dbd65719631c

PE Executable
MD5: c5c6ccefaec1268d1e02dbd65719631c
Size: 1.66 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 c5c6ccefaec1268d1e02dbd65719631c
Sha1 2654ead8fc44a3fd7ba658039f1de05de3467e18
Sha256 a3f7c663787c2a28ec9cef7721cedc83d6bdf75fff5a54745981686c7f355c71
Sha384 b0528e4518a8718c116fa1d566b2b522cf4b3bb2b4b5d58d5196256a83da1b4d5a2a07b5888fa091b7e89b08c187ade9
Sha512 656c46513cab84a5ab45ebc639bc4684b1ee2f652265707f64d97ecaf79605f8367691f0b716ede91ce56d115eee7fe10f4404fa7c408aa750e1df6c7f9e4303
SSDeep 24576:0yzYqjHyzZ4achmNEQ3I1dfgaGZpIj0qjQoBmihntftnNxW6d9+8A8riMs6bOxb9:tLjSzigEQ3eWaMIQnogiht1j9+dxh
TLSH 937533C9B7D9610DED8A66770DC2C59AEBFF24D84B4825DE1E7F105C4672202A842FF8
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Overlay_d8355c6c.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Int32 Stub.Program::Main(System.String[])
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
10.0.26100.2161
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
152
Main Method
System.Int32 Stub.Program::Main(System.String[])
Main IL Instruction Count
97
Main IL
ldstr SYSRUNTIME_CTX
call System.String System.Environment::GetEnvironmentVariable(System.String)
dup <null>
brtrue.s IL_0013: stloc.0
pop <null>
ldstr 
stloc.0 <null>
ldloc.0 <null>
ldstr d3c0y
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_0029: ldloc.0
ldc.i4.m1 <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldc.i4.0 <null>
ret <null>
ldloc.0 <null>
ldstr r3a1
call System.Boolean System.String::op_Inequality(System.String,System.String)
brfalse.s IL_0065: call System.Void Stub.Program::AntiSandboxDelay()
ldc.i4.0 <null>
stloc.3 <null>
call System.ValueTuple`2<Stub.StubConfig,System.Byte[]> Stub.Program::ReadFromOverlay()
ldfld Stub.StubConfig System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item1
callvirt System.Boolean Stub.StubConfig::get_EnableStealthCopy()
stloc.3 <null>
leave.s IL_004D: ldloc.3
pop <null>
leave.s IL_004D: ldloc.3
ldloc.3 <null>
brfalse.s IL_0056: ldstr "SYSRUNTIME_CTX"
call System.Int32 Stub.Program::RelaunchWithRandomName()
ret <null>
ldstr SYSRUNTIME_CTX
ldstr r3a1
call System.Void System.Environment::SetEnvironmentVariable(System.String,System.String)
call System.Void Stub.Program::AntiSandboxDelay()
call System.ValueTuple`2<Stub.StubConfig,System.Byte[]> Stub.Program::ReadFromOverlay()
dup <null>
ldfld Stub.StubConfig System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item1
stloc.1 <null>
ldfld System.Byte[] System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item2
stloc.2 <null>
leave.s IL_0099: ldloc.1
stloc.s V_4
ldstr Load Error
ldloc.s V_4
callvirt System.String System.Exception::get_Message()
call System.Void Stub.Program::ShowError(System.String,System.String)
ldc.i4.1 <null>
stloc.s V_5
leave IL_011A: ldloc.s V_5
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_EnableGuard()
brfalse.s IL_00AC: ldloc.1
ldloc.1 <null>
call System.Void Stub.Guard::set_Config(Stub.StubConfig)
call System.Void Stub.Guard::StartMonitoring()
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_EnableDecoy()
brfalse.s IL_00B9: nop
call System.Void Stub.Decoy::Spawn()
nop <null>
ldloc.2 <null>
ldloc.1 <null>
callvirt System.Byte[] Stub.StubConfig::get_KeyBytes()
ldloc.1 <null>
callvirt System.Byte[] Stub.StubConfig::get_IVBytes()
call System.Byte[] Stub.Program::DecryptPayload(System.Byte[],System.Byte[],System.Byte[])
stloc.s V_6
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_InMemory()
brtrue.s IL_00E6: ldloc.s V_6
ldloc.s V_6
ldloc.1 <null>
callvirt System.String Stub.StubConfig::get_OriginalFileName()
ldarg.0 <null>
call System.Int32 Stub.Program::ExecuteFromDisk(System.Byte[],System.String,System.String[])
br.s IL_00F4: call System.Void Stub.Decoy::Kill()
ldloc.s V_6
ldloc.1 <null>
callvirt System.String Stub.StubConfig::get_OriginalFileName()
ldarg.0 <null>
call System.Int32 Stub.Program::ExecuteManaged(System.Byte[],System.String,System.String[])
call System.Void Stub.Decoy::Kill()
stloc.s V_5
leave.s IL_011A: ldloc.s V_5
stloc.s V_7
ldstr Error
ldloc.s V_7
callvirt System.String System.Exception::get_Message()
call System.Void Stub.Program::ShowError(System.String,System.String)
call System.Void Stub.Decoy::Kill()
ldc.i4.1 <null>
stloc.s V_5
leave.s IL_011A: ldloc.s V_5
ldloc.s V_5
ret <null>
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_d8355c6c.bin (1624686 bytes)
Info
PDB Path: ?
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Int32 Stub.Program::Main(System.String[])
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
10.0.26100.2161
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
152
Main Method
System.Int32 Stub.Program::Main(System.String[])
Main IL Instruction Count
97
Main IL
ldstr SYSRUNTIME_CTX
call System.String System.Environment::GetEnvironmentVariable(System.String)
dup <null>
brtrue.s IL_0013: stloc.0
pop <null>
ldstr 
stloc.0 <null>
ldloc.0 <null>
ldstr d3c0y
call System.Boolean System.String::op_Equality(System.String,System.String)
brfalse.s IL_0029: ldloc.0
ldc.i4.m1 <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldc.i4.0 <null>
ret <null>
ldloc.0 <null>
ldstr r3a1
call System.Boolean System.String::op_Inequality(System.String,System.String)
brfalse.s IL_0065: call System.Void Stub.Program::AntiSandboxDelay()
ldc.i4.0 <null>
stloc.3 <null>
call System.ValueTuple`2<Stub.StubConfig,System.Byte[]> Stub.Program::ReadFromOverlay()
ldfld Stub.StubConfig System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item1
callvirt System.Boolean Stub.StubConfig::get_EnableStealthCopy()
stloc.3 <null>
leave.s IL_004D: ldloc.3
pop <null>
leave.s IL_004D: ldloc.3
ldloc.3 <null>
brfalse.s IL_0056: ldstr "SYSRUNTIME_CTX"
call System.Int32 Stub.Program::RelaunchWithRandomName()
ret <null>
ldstr SYSRUNTIME_CTX
ldstr r3a1
call System.Void System.Environment::SetEnvironmentVariable(System.String,System.String)
call System.Void Stub.Program::AntiSandboxDelay()
call System.ValueTuple`2<Stub.StubConfig,System.Byte[]> Stub.Program::ReadFromOverlay()
dup <null>
ldfld Stub.StubConfig System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item1
stloc.1 <null>
ldfld System.Byte[] System.ValueTuple`2<Stub.StubConfig,System.Byte[]>::Item2
stloc.2 <null>
leave.s IL_0099: ldloc.1
stloc.s V_4
ldstr Load Error
ldloc.s V_4
callvirt System.String System.Exception::get_Message()
call System.Void Stub.Program::ShowError(System.String,System.String)
ldc.i4.1 <null>
stloc.s V_5
leave IL_011A: ldloc.s V_5
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_EnableGuard()
brfalse.s IL_00AC: ldloc.1
ldloc.1 <null>
call System.Void Stub.Guard::set_Config(Stub.StubConfig)
call System.Void Stub.Guard::StartMonitoring()
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_EnableDecoy()
brfalse.s IL_00B9: nop
call System.Void Stub.Decoy::Spawn()
nop <null>
ldloc.2 <null>
ldloc.1 <null>
callvirt System.Byte[] Stub.StubConfig::get_KeyBytes()
ldloc.1 <null>
callvirt System.Byte[] Stub.StubConfig::get_IVBytes()
call System.Byte[] Stub.Program::DecryptPayload(System.Byte[],System.Byte[],System.Byte[])
stloc.s V_6
ldloc.1 <null>
callvirt System.Boolean Stub.StubConfig::get_InMemory()
brtrue.s IL_00E6: ldloc.s V_6
ldloc.s V_6
ldloc.1 <null>
callvirt System.String Stub.StubConfig::get_OriginalFileName()
ldarg.0 <null>
call System.Int32 Stub.Program::ExecuteFromDisk(System.Byte[],System.String,System.String[])
br.s IL_00F4: call System.Void Stub.Decoy::Kill()
ldloc.s V_6
ldloc.1 <null>
callvirt System.String Stub.StubConfig::get_OriginalFileName()
ldarg.0 <null>
call System.Int32 Stub.Program::ExecuteManaged(System.Byte[],System.String,System.String[])
call System.Void Stub.Decoy::Kill()
stloc.s V_5
leave.s IL_011A: ldloc.s V_5
stloc.s V_7
ldstr Error
ldloc.s V_7
callvirt System.String System.Exception::get_Message()
call System.Void Stub.Program::ShowError(System.String,System.String)
call System.Void Stub.Decoy::Kill()
ldc.i4.1 <null>
stloc.s V_5
leave.s IL_011A: ldloc.s V_5
ldloc.s V_5
ret <null>
Overlay_d8355c6c.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙