Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5: d1ecbcbae1ba214c0d5ae1b2edba55fd
Size: 77.82 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 d1ecbcbae1ba214c0d5ae1b2edba55fd
Sha1 c5a85181d8985fba60485dad1e5d8f78046315c8
Sha256 432be80b43a6e63fdbfe7487d2bd2dbba90281c03fc95a15fcac91f1f2f7c589
Sha384 c256201c769c91377f44a773171486dafe6f6fdcc3ba0331bc2b9b20288de68033775d52ed1d968bcf540c4958f03cc4
Sha512 4977a621e7bf7dd299bc5876d25d4e0aadaaf3a3a6af24d767c39aea75cf28f12770187217f49a83a3d9de639113a1c3e66fddf98cb092ced7db6c792486d563
SSDeep 768:xDJ6dbYT5PG1q5+nCMI0boPaVr572GxXGmdxfsRNa0GY4JsiTBincnAGEaDDp5BH:xdH0MJaSaVr59502pinKAGXDpTk97JG
TLSH 1D734B18BBEBC522D1AD9A7984E113050375E7573603DB5F2CC803A94F23BC79F46A9A
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Client.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
Config. Field Value
Key (AES_256) OXZaVXhuhuhuhuhuhuhuhuhuhuhu
Pastebin -huhuhuhu
Certificate MIIE8jhuhuhuhuhuhuhuhuhuhuhu
ServerSignature hwenOLhuhuhuhuhuhuhuhuhuhuhu
Install fhuhuhuhu
BDOS fhuhuhuhu
Anti-VM fhuhuhuhu
Install-Folder %Aphuhuhuhu
Version 0.huhuhuhu
Hosts francihuhuhuhuhuhuhuhuhuhuhu
Ports 3huhuhuhu
Mutex Asynchuhuhuhuhuhuhu
Delay 3huhuhuhu
Group Rahuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Raagts03.exe
Full Name
Raagts03.exe
EntryPoint
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Scope Name
Raagts03.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Raagts03
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
135
Main Method
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Main IL Instruction Count
3
Main IL
call System.Void hyBi4B7CHOZ0PcM2da.BrEOWILUFmZ9AtRTw7::lLHifFIsCLsZtjvFfN0i()
call System.Void Client.Program::Main()
ret <null>
Module Name
Raagts03.exe
Full Name
Raagts03.exe
EntryPoint
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Scope Name
Raagts03.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Raagts03
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
135
Main Method
System.Void <PrivateImplementationDetails>{C9D51624-7BE3-4530-BBD7-5A7744545664}::Main()
Main IL Instruction Count
3
Main IL
call System.Void hyBi4B7CHOZ0PcM2da.BrEOWILUFmZ9AtRTw7::lLHifFIsCLsZtjvFfN0i()
call System.Void Client.Program::Main()
ret <null>
Key (AES_256) MUTEXmalicious
OXZaVXhuhuhuhuhuhuhuhuhuhuhu
CnC CNCmalicious
francihuhuhuhuhuhuhuhuhuhuhu
Ports PORTmalicious
3huhuhuhu
Mutex MUTEXmalicious
Asynchuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
An error has occurred. This application may no longer respond until reloaded. Reload 🗙