Malicious
Malicious

PE Executable
MD5: c7b5a111744b16106c9120ebf726e982
Size: 356.86 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 c7b5a111744b16106c9120ebf726e982
Sha1 a77d5d5f20e48eb05fc9051be4e643e19cb86ebd
Sha256 268501cbc4704142a83673aab0b20dc7b8bf9221b70f0e7bbb42f072ed341e7a
Sha384 d7c11e41dfc29de44ec559da9575833fc73640f4df7065571638ba554162293b7f1431ad79daa0bb9ab59c7fc5a67d2a
Sha512 5eff9b6fe4c8e23fdb8d24787235a32be0fbdb5537037088e48127a3a30260a73371de042f68b73ac21e93affc2536b3d52982210199e5b23fa5c27550f47f28
SSDeep 6144:Q2+EMJ1kbrTzS+QbZVuZV3zbOBUciMAFRzeI5GgFuj:fS1ki+RcRiMspeQGgFs
TLSH E6746B2373A4A93BD1BD173AE43206056BF4D507BB16E38B5A6845BC6D233828D917F3
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port jul505huhuhuhuhuhuhu
Host jul505huhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port 5huhuhuhu
Host jul505huhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port 5huhuhuhu
Host jul505huhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port 5huhuhuhu
Host jul505huhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port 5huhuhuhu
Host jul505huhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port 5huhuhuhu
Host jul505huhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory Suhuhuhuhu
InstallName Clihuhuhuhu
Install 0huhuhuhu
Startup 0huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey Quasahuhuhuhuhuhuhu
HideFile 0huhuhuhu
EnableLogger 1huhuhuhu
Tag Ofhuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::易쒉늮蠃ℂ鯯汊弮꫉易嵩雚偆�⣊䧜(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean �貇퍖庯멬ꂾ뉜礫渰䙮穛푑㨶㞣穉岆됽⁦䃕::䯱脍硚౺�欳䀅זּ낎칪뮀Ꜯ錱–㝠黧۽()
brfalse.s IL_0040: call System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::鯎ᘼ짾砲粊쾐ꤧ졭ﲭ悬坖뤽돫㹾䆲騃횂()
call System.Boolean 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::輄乑勰畲㔩킟챎ᯏ䅂팺亝꡶恵鍟ά乥ꚿ렝()
brfalse.s IL_0040: call System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::鯎ᘼ짾砲粊쾐ꤧ졭ﲭ悬坖뤽돫㹾䆲騃횂()
call System.Boolean 蛁䩿끗촙䊵�턯櫡띳녚㠺醳睢ꉍ╴䮣ṹ붋::get_Exiting()
brtrue.s IL_0040: call System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::鯎ᘼ짾砲粊쾐ꤧ졭ﲭ悬坖뤽돫㹾䆲騃횂()
ldsfld 蛁䩿끗촙䊵�턯櫡띳녚㠺醳睢ꉍ╴䮣ṹ붋 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::땿ሩ䪭踌饼毌䫈눛鬄沉庸㧆꩎崮衡쇳᭱
callvirt System.Void 蛁䩿끗촙䊵�턯櫡띳녚㠺醳睢ꉍ╴䮣ṹ붋::⯮䆑�瀐禭筰ꂠ࣎팈攌⧏풨ꛌΏ㎽띶꤈()
call System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::鯎ᘼ짾砲粊쾐ꤧ졭ﲭ悬坖뤽돫㹾䆲騃횂()
call System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::⑴잼鹝釋崼⮥ꀴ붼ࠝ╕⺠㴆긘粞囎爫퀉ɯ毐()
ret <null>
Module Name
Client.exe
Full Name
Client.exe
EntryPoint
System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::Main(System.String[])
Scope Name
Client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Client
Assembly Version
1.3.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
896
Main Method
System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::Main(System.String[])
Main IL Instruction Count
19
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
call System.AppDomain System.AppDomain::get_CurrentDomain()
ldnull <null>
ldftn System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::易쒉늮蠃ℂ鯯汊弮꫉易嵩雚偆�⣊䧜(System.Object,System.UnhandledExceptionEventArgs)
newobj System.Void System.UnhandledExceptionEventHandler::.ctor(System.Object,System.IntPtr)
callvirt System.Void System.AppDomain::add_UnhandledException(System.UnhandledExceptionEventHandler)
call System.Boolean �貇퍖庯멬ꂾ뉜礫渰䙮穛푑㨶㞣穉岆됽⁦䃕::䯱脍硚౺�欳䀅זּ낎칪뮀Ꜯ錱–㝠黧۽()
brfalse.s IL_0040: call System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::鯎ᘼ짾砲粊쾐ꤧ졭ﲭ悬坖뤽돫㹾䆲騃횂()
call System.Boolean 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::輄乑勰畲㔩킟챎ᯏ䅂팺亝꡶恵鍟ά乥ꚿ렝()
brfalse.s IL_0040: call System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::鯎ᘼ짾砲粊쾐ꤧ졭ﲭ悬坖뤽돫㹾䆲騃횂()
call System.Boolean 蛁䩿끗촙䊵�턯櫡띳녚㠺醳睢ꉍ╴䮣ṹ붋::get_Exiting()
brtrue.s IL_0040: call System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::鯎ᘼ짾砲粊쾐ꤧ졭ﲭ悬坖뤽돫㹾䆲騃횂()
ldsfld 蛁䩿끗촙䊵�턯櫡띳녚㠺醳睢ꉍ╴䮣ṹ붋 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::땿ሩ䪭踌饼毌䫈눛鬄沉庸㧆꩎崮衡쇳᭱
callvirt System.Void 蛁䩿끗촙䊵�턯櫡띳녚㠺醳睢ꉍ╴䮣ṹ붋::⯮䆑�瀐禭筰ꂠ࣎팈攌⧏풨ꛌΏ㎽띶꤈()
call System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::鯎ᘼ짾砲粊쾐ꤧ졭ﲭ悬坖뤽돫㹾䆲騃횂()
call System.Void 둨쨾ợ垷⮳郄尨퇒镼鹲櫸籾繈ﻴ凜::⑴잼鹝釋崼⮥ꀴ붼ࠝ╕⺠㴆긘粞囎爫퀉ɯ毐()
ret <null>
CnC CNCmalicious
jul505huhuhuhuhuhuhu
Port PORTmalicious
5huhuhuhu
CnC CNCmalicious
jul505huhuhuhuhuhuhu
CnC CNCmalicious
jul505huhuhuhuhuhuhu
CnC CNCmalicious
jul505huhuhuhuhuhuhu
CnC CNCmalicious
jul505huhuhuhuhuhuhu
CnC CNCmalicious
jul505huhuhuhuhuhuhu
Port PORTmalicious
jul505huhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
xClient.Properties.Resources.resources
information
[NBF]root.Data
[NBF]root.Data-preview.png
Config. Field Value
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port jul505huhuhuhuhuhuhu
Host jul505huhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port 5huhuhuhu
Host jul505huhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port 5huhuhuhu
Host jul505huhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port 5huhuhuhu
Host jul505huhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Conf. AES-Salt BF-EB-huhuhuhuhuhuhuhuhuhuhu
Port 5huhuhuhu
Host jul505huhuhuhuhuhuhu
Conf. AES-Key EQ989Dhuhuhuhuhuhuhu
Version 1.huhuhuhu
Port 5huhuhuhu
Host jul505huhuhuhuhuhuhu
ReconnectDelay 3huhuhuhu
Key 1WvgEMhuhuhuhuhuhuhu
AuthKey NcFtjbhuhuhuhuhuhuhuhuhuhuhu
SubDirectory Suhuhuhuhu
InstallName Clihuhuhuhu
Install 0huhuhuhu
Startup 0huhuhuhu
Mutex QSR_Mhuhuhuhuhuhuhu
StartupKey Quasahuhuhuhuhuhuhu
HideFile 0huhuhuhu
EnableLogger 1huhuhuhu
Tag Ofhuhuhuhu
LogDirectory Lhuhuhuhu
HideLogDirectory 0huhuhuhu
HideLogSubdirectory 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
CnC CNCmalicious
jul505huhuhuhuhuhuhu
c7b5a111744b16106c9120ebf726e982
Port PORTmalicious
5huhuhuhu
c7b5a111744b16106c9120ebf726e982
CnC CNCmalicious
jul505huhuhuhuhuhuhu
c7b5a111744b16106c9120ebf726e982
CnC CNCmalicious
jul505huhuhuhuhuhuhu
c7b5a111744b16106c9120ebf726e982
CnC CNCmalicious
jul505huhuhuhuhuhuhu
c7b5a111744b16106c9120ebf726e982
CnC CNCmalicious
jul505huhuhuhuhuhuhu
c7b5a111744b16106c9120ebf726e982
CnC CNCmalicious
jul505huhuhuhuhuhuhu
c7b5a111744b16106c9120ebf726e982
Port PORTmalicious
jul505huhuhuhuhuhuhu
c7b5a111744b16106c9120ebf726e982
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙