Malicious
Malicious

c9b8fcaa3ec2df09aade3bfa52f6a1a9

PE Executable
MD5: c9b8fcaa3ec2df09aade3bfa52f6a1a9
Size: 48.64 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 c9b8fcaa3ec2df09aade3bfa52f6a1a9
Sha1 aa2b324fcde776b2008ceaff2080c761535130f1
Sha256 f45ee7d02115d754375ae4bf7ad74a51a64565f41efad4b0d85444232723c5f4
Sha384 01e0e0dcb2bf8a61a0ff8684ef76cf6049f2e439a33f0a5d9ba4a2bd04a58fdde99406e86a65035e85a6eea59fd69e75
Sha512 9006ae0944140ea3bc1a8df6fb203f5df2b2caa97cd5a6eddb986ee16ac6b5f6bdf689729eda15e8f4fdd76c6114263248a455acbe7e18229eb3c25cc0cb901b
SSDeep 768:MuYHKTsufqG9vSLjWUvlPRmo2qbsOvFNEnNaIxPImqSomd0bqrZN20WrlTcSnJcK:MuYHKTsjMvSX2DOvvs+mqSom6bqzirhL
TLSH D3231A0037E9C16BF2BE4F7869F26245857BF2637603D6492CC441975B13FC29A42AEE
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Key (AES_256) alJxeEhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature VhNpCjhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS thuhuhuhu
Anti-VM thuhuhuhu
Install File Chromhuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts ryanhuhuhuhuhuhuhu
Ports 4huhuhuhu
Mutex II9yhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group ryanhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Module Name
ZpKCwPNBXuB
Full Name
ZpKCwPNBXuB
EntryPoint
System.Void ZJKVppIgjC.ynhvwlrNzMmXW::Main()
Scope Name
ZpKCwPNBXuB
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tgryan
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void ZJKVppIgjC.ynhvwlrNzMmXW::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::VyjwLYkxRQtNz
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean ZJKVppIgjC.yiMgEjjmgHt::AELIToYrRbz()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean TinVvsPLVfENuVQ.LWsROHUXNsQ::eoQOojwaLkyke()
brtrue IL_0043: ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::VLrukKZwaGaAA
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::VLrukKZwaGaAA
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::ryrgNnlMDBgP
call System.Void TinVvsPLVfENuVQ.BnyBIclvXxMHH::UUtajyDSmC()
ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::ryrgNnlMDBgP
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::RNZNetfOdvP
call System.Void YJeegUrkidnT.yuPlBejrzSL::MJkxWSzGvsuL()
ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::RNZNetfOdvP
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void TinVvsPLVfENuVQ.iolEXIKFbzYZU::rclmfgFphGxlhQ()
call System.Boolean TinVvsPLVfENuVQ.iolEXIKFbzYZU::FKadqyXhuUBQ()
brfalse IL_0089: call System.Void TinVvsPLVfENuVQ.iolEXIKFbzYZU::rclmfgFphGxlhQ()
call System.Void TinVvsPLVfENuVQ.MheiGNihUEI::NYYiutrIhFA()
call System.Void TinVvsPLVfENuVQ.iolEXIKFbzYZU::rclmfgFphGxlhQ()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean mwjGKjLGijsGG.XadIaZmyoelbVz::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void mwjGKjLGijsGG.XadIaZmyoelbVz::yVkQthECja()
call System.Void mwjGKjLGijsGG.XadIaZmyoelbVz::sLazNrhrIliovKo()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Info
PE Detect: PeReader OK (file layout)
Module Name
ZpKCwPNBXuB
Full Name
ZpKCwPNBXuB
EntryPoint
System.Void ZJKVppIgjC.ynhvwlrNzMmXW::Main()
Scope Name
ZpKCwPNBXuB
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
tgryan
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0,Profile=Client
Total Strings
120
Main Method
System.Void ZJKVppIgjC.ynhvwlrNzMmXW::Main()
Main IL Instruction Count
51
Main IL
ldc.i4.0 <null>
stloc.0 <null>
br IL_0015: ldloc.0
ldc.i4 1000
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldloc.0 <null>
ldc.i4.1 <null>
add <null>
stloc.0 <null>
ldloc.0 <null>
ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::VyjwLYkxRQtNz
call System.Int32 System.Convert::ToInt32(System.String)
blt.s IL_0007: ldc.i4 1000
call System.Boolean ZJKVppIgjC.yiMgEjjmgHt::AELIToYrRbz()
brtrue IL_0032: nop
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
nop <null>
call System.Boolean TinVvsPLVfENuVQ.LWsROHUXNsQ::eoQOojwaLkyke()
brtrue IL_0043: ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::VLrukKZwaGaAA
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::VLrukKZwaGaAA
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0057: ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::ryrgNnlMDBgP
call System.Void TinVvsPLVfENuVQ.BnyBIclvXxMHH::UUtajyDSmC()
ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::ryrgNnlMDBgP
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_006B: ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::RNZNetfOdvP
call System.Void YJeegUrkidnT.yuPlBejrzSL::MJkxWSzGvsuL()
ldsfld System.String ZJKVppIgjC.yiMgEjjmgHt::RNZNetfOdvP
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse IL_0089: call System.Void TinVvsPLVfENuVQ.iolEXIKFbzYZU::rclmfgFphGxlhQ()
call System.Boolean TinVvsPLVfENuVQ.iolEXIKFbzYZU::FKadqyXhuUBQ()
brfalse IL_0089: call System.Void TinVvsPLVfENuVQ.iolEXIKFbzYZU::rclmfgFphGxlhQ()
call System.Void TinVvsPLVfENuVQ.MheiGNihUEI::NYYiutrIhFA()
call System.Void TinVvsPLVfENuVQ.iolEXIKFbzYZU::rclmfgFphGxlhQ()
leave IL_0099: nop
pop <null>
leave IL_0099: nop
nop <null>
call System.Boolean mwjGKjLGijsGG.XadIaZmyoelbVz::get_IsConnected()
brtrue IL_00AE: leave IL_00B9
call System.Void mwjGKjLGijsGG.XadIaZmyoelbVz::yVkQthECja()
call System.Void mwjGKjLGijsGG.XadIaZmyoelbVz::sLazNrhrIliovKo()
leave IL_00B9: ldc.i4 5000
pop <null>
leave IL_00B9: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
br.s IL_0099: nop
Key (AES_256) MUTEXmalicious
alJxeEhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
ryanhuhuhuhuhuhuhu
Ports PORTmalicious
4huhuhuhu
Mutex MUTEXmalicious
II9yhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Key (AES_256) alJxeEhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature VhNpCjhuhuhuhuhuhuhuhuhuhuhu
Install thuhuhuhu
BDOS thuhuhuhu
Anti-VM thuhuhuhu
Install File Chromhuhuhuhuhuhuhu
Install-Folder %Aphuhuhuhu
Hosts ryanhuhuhuhuhuhuhu
Ports 4huhuhuhu
Mutex II9yhuhuhuhu
Version 0huhuhuhu
Delay 3huhuhuhu
Group ryanhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Key (AES_256) MUTEXmalicious
alJxeEhuhuhuhuhuhuhuhuhuhuhu
c9b8fcaa3ec2df09aade3bfa52f6a1a9
CnC CNCmalicious
ryanhuhuhuhuhuhuhu
c9b8fcaa3ec2df09aade3bfa52f6a1a9
Ports PORTmalicious
4huhuhuhu
c9b8fcaa3ec2df09aade3bfa52f6a1a9
Mutex MUTEXmalicious
II9yhuhuhuhu
c9b8fcaa3ec2df09aade3bfa52f6a1a9
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙