Malicious
Malicious

cee0e495adc06bbac4be33544bd393ca

Share on LinkedIn
Print
PE Executable
MD5: cee0e495adc06bbac4be33544bd393ca
Size: 272.9 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 cee0e495adc06bbac4be33544bd393ca
Sha1 b65b3aba7086a8db3b452f171782af7eab4cbeb5
Sha256 e95766d2d9dcc598cada3c33133935fda7d54d245d8a46fc05be47986e036fff
Sha384 f85a042095f83bd8b630b53e3ee5db61f0c0714529593fe88c1d77d6743d2bd799f2eb708f2063cee2dd3585d722963b
Sha512 c5e118656fb591e17dd15a82d33ead289fc5c93e1aec92721d2ad435625b7f34cd3b7e0f24f760f70c770b4a3dcea93f75210d738546568d0c6f987640cbb0a2
SSDeep 3072:xMDnk5ELWDhwsNMDzXExI3pmUHLB2VsgyxTOao8oY0h6:xMwwWvMDrtgSTXLV0
TLSH 76447317AB79AC0BC25CC6309CB6E278A5EC2E67DC1CC708ABC19D5F762718E8D0465D
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0-preview.png
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
ID:000B
ID:0
ID:000C
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
packet_size [b] 5huhuhuhu
BD [BD] Fhuhuhuhu
directory [DR] AllUshuhuhuhuhuhuhu
executable_name [EXE] Razerhuhuhuhuhuhuhu
cnc_host [H] 1oewryhuhuhuhuhuhuhu
is_dir_defined [Idr] Thuhuhuhu
Anti_CH Fhuhuhuhu
is_startup_folder [IsF] Thuhuhuhu
USB_SP Fhuhuhuhu
is_user_reg [Isu] Thuhuhuhu
cnc_port [P] 5huhuhuhu
reg_key [RG] 21f49chuhuhuhuhuhuhuhuhuhuhu
reg_path [sf] Softwahuhuhuhuhuhuhuhuhuhuhu
victim_name [VN] khuhuhuhu
version [VR] <- NjRhuhuhuhuhuhuhuhuhuhuhu
splitter [Y] Y262huhuhuhu
MSGE Dihuhuhuhu
MSGT Thhuhuhuhu
MSGB Sorry,huhuhuhuhuhuhuhuhuhuhu
MSGSYM vbChuhuhuhu
OBITO Dihuhuhuhu
TSKE Dihuhuhuhu
TSK Wirehuhuhuhuhuhuhu
KAKASHI Dihuhuhuhu
AKATSUKI Dihuhuhuhu
CLEANSWEEP Dihuhuhuhu
PASTEE Dihuhuhuhu
PASTEBIN https:huhuhuhuhuhuhuhuhuhuhu
CLIP nhuhuhuhu
UAC Dihuhuhuhu
nowifi ohuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
539
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
Module Name
Stub.exe
Full Name
Stub.exe
EntryPoint
System.Void j.A::main()
Scope Name
Stub.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v2.0.50727
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Stub
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
539
Main Method
System.Void j.A::main()
Main IL Instruction Count
2
Main IL
call System.Void j.OK::ko()
ret <null>
CnC CNCmalicious
1oewryhuhuhuhuhuhuhu
Port PORTmalicious
5huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙