Malicious
Malicious

d1336fe4db7f56d197047043bc1a8c1b

Share on LinkedIn
Print
PE Executable
MD5: d1336fe4db7f56d197047043bc1a8c1b
Size: 3.92 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d1336fe4db7f56d197047043bc1a8c1b
Sha1 a67217f713cee6b314440820b714a760e394e77a
Sha256 5c8e45cbc43e5e7b15d41c0e4bf245e9b904b4d316db90448ecf10e6eb080ece
Sha384 cd7055ada74adbd9c299ec8573b7a26de0c19580758a915b19d3853b48d9da0ffcb80578703ab589e8c70f7327a08fed
Sha512 e547c99cb09d42057a66a65293143f32b31b1b3c74e3dc48552a89929c05c10d9a77fb98dd26d89ffd97e829e21110f69b6e69c6f080ab44f80a06ddb7c1459d
SSDeep 49152:tGZhgzYjzsolLD5j9WuI9NuHzDUcJ2TTQYq6Flx2WF0gXI0C0dgSOIU6ipS:6tAz981Gx2aPlmS5+pS
TLSH 2C064A02BE8659E9C1DDC870C3478B634A2274CB1A36F6AF42E501253F6EBB55F2C359
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft Team
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet ������huhuhuhuhuhuhuhuhuhuhu
UserAgent x-@��huhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet instaghuhuhuhuhuhuhuhuhuhuhu
UserAgent ccept*huhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet oNitrohuhuhuhuhuhuhuhuhuhuhu
UserAgent ????huhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet +,-./0huhuhuhuhuhuhuhuhuhuhu
UserAgent \Operhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet \s+"([huhuhuhuhuhuhuhuhuhuhu
UserAgent )��?Q0huhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet cko)%2huhuhuhuhuhuhuhuhuhuhu
UserAgent gh_typhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet idfollhuhuhuhuhuhuhuhuhuhuhu
UserAgent rustc/huhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet peapplhuhuhuhuhuhuhuhuhuhuhu
UserAgent registhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet 540724huhuhuhuhuhuhuhuhuhuhu
UserAgent ������huhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet 3860/lhuhuhuhuhuhuhuhuhuhuhu
UserAgent @���Chuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet �����huhuhuhuhuhuhuhuhuhuhu
UserAgent s/authhuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet [+] huhuhuhuhuhuhuhuhuhuhu
UserAgent ame$hthuhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet x150&fhuhuhuhuhuhuhuhuhuhuhu
UserAgent 807616huhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet 4d7976huhuhuhuhuhuhuhuhuhuhu
UserAgent s�����huhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
C2 https:huhuhuhuhuhuhuhuhuhuhu
Botnet ������huhuhuhuhuhuhuhuhuhuhu
UserAgent 807616huhuhuhuhuhuhuhuhuhuhu
[Configuration Offset] 0x0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: wipe_software.pdb
An error has occurred. This application may no longer respond until reloaded. Reload 🗙