Malicious
PE Executable
MD5: c6fa433638c26773708cb30d81b98aef
Size: 6.57 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | c6fa433638c26773708cb30d81b98aef |
| Sha1 | 1f45ca0c3e317b7483c031f95806d407a80faabb |
| Sha256 | 46bdc54ed6ca8f9200d5445880c687d0e3730ec8adb9b5d57f420b951aa2be68 |
| Sha384 | 84f307f0894ee0f226f4ac6ce7a2632cc5030b3d625a20dd23f6020b93ca57bd38a1f2d66bb696187c82231e89b36bc1 |
| Sha512 | dc11d66c56bd41230af244e167aab25cc8d4dba793838080a5d90321af18da7410b793c190194ff6ff9bd9fc1a16df3d27f574ba2f3cb739c236e4b6d9bf63bc |
| SSDeep | 196608:usSbk9fcCkbVN8iNIS8TkSIviB6tQJmUci4gFx:us2CkbXWkS0tQGiTb |
| TLSH | E26633194BD11D98EB7301399CB87041CAE5B662FD43DFEC4746220E48AABCF5A2B375 |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Malicious
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
4 / 4
Path
pe:exe>pe:dll>pe:rsrc>bin
Shape
pe:exe>pe:dll>pe:rsrc>bin
malicious
4 nodes
Path
pe:exe>pe:dll>bin
Shape
pe:exe>pe:dll>bin
malicious
3 nodes
| Config. Field | Value |
|---|---|
| Conf. AES-Salt | BF-EB-huhuhuhuhuhuhuhuhuhuhu |
| Conf. AES-Key | |
| Version | Objehuhuhuhu |
| Port | Chainhuhuhuhuhuhuhu |
| Host | Chainhuhuhuhuhuhuhu |
| ReconnectDelay | Authhuhuhuhuhuhuhu |
| Key | Chaihuhuhuhu |
| SubDirectory | Keyhuhuhuhu |
| InstallName | Ahuhuhuhu |
| Install | Microshuhuhuhuhuhuhuhuhuhuhu |
| Startup | 1huhuhuhu |
| Mutex | 1huhuhuhu |
| StartupKey | -10huhuhuhu |
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
| Name | Value |
|---|---|
| Module Name | RedDolphinClient.exe |
| Full Name | RedDolphinClient.exe |
| EntryPoint | System.Void RedDolphinClient.Program::<Main>(System.String[]) |
| Scope Name | RedDolphinClient.exe |
| Scope Type | ModuleDef |
| Kind | Console |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | RedDolphinClient |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 419 |
| Main Method | System.Void RedDolphinClient.Program::<Main>(System.String[]) |
| Main IL Instruction Count | 7 |
| Main IL | |
| Info | PE Detect: PeReader OK (file layout) |
| Info | |
| Module Name | RedDolphinClient.exe |
| Full Name | RedDolphinClient.exe |
| EntryPoint | System.Void RedDolphinClient.Program::<Main>(System.String[]) |
| Scope Name | RedDolphinClient.exe |
| Scope Type | ModuleDef |
| Kind | Console |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | RedDolphinClient |
| Assembly Version | 1.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.7.2 |
| Total Strings | 419 |
| Main Method | System.Void RedDolphinClient.Program::<Main>(System.String[]) |
| Main IL Instruction Count | 7 |
| Main IL | |
CnC
CNCmalicious
Chainhuhuhuhuhuhuhu
Port
PORTmalicious
Chainhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential