Malicious
Malicious

d7e149f1ca913d1858ddabfdd1d99225

PE Executable
MD5: d7e149f1ca913d1858ddabfdd1d99225
Size: 37.38 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 d7e149f1ca913d1858ddabfdd1d99225
Sha1 85af2dbe31ec4e05ba8ef046dcff4f6b08a3d5cc
Sha256 3e97680e06a1593784588bb0e7b98ff1a5cb4809eee5aeb149840017f5714e45
Sha384 5e2b77f4303eecd41fef6591f863ae8dab0cbee9fd174ac0890b44cf515f473276bf8d2498359ab051969a77f25db62d
Sha512 610e13e5fede8feb60512e7d7b40b38942a4ab65d15f54b0d3f1a076056dd2367e92bdb5b018a0a1614b9bb31164c525c231939f4ee250d8135d934ce98c81d8
SSDeep 768:x6KkDnV2jZgWSV+J+51Tnx0/Fn9aH6TOMh932:xfb8QwtnxYFn9aH6TOMTG
TLSH 88F24B083BD54229CBFE7FF95AB366061770E5078A03DB4D0DD8899E6B27BC589007E6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:rsrc>bin
Shape pe:exe>pe:rsrc>bin
malicious 3 nodes
Config. Field Value
Mutex U3dUchuhuhuhuhuhuhu
Hosts 155.huhuhuhuhuhuhu
Port 1huhuhuhu
KEY <V7PVhuhuhuhuhuhuhu
USBNM <Xwhuhuhuhu
family xhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
XWorm yu august.exe
Full Name
XWorm yu august.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
XWorm yu august.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XWorm yu august
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
197
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
64
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::Hosts
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Hosts
ldsfld System.String Settings::Port
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Port
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00AB: call System.Void Stub.Main::Exclusion()
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Stub.Main::Exclusion()
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.0 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__3()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldloc.0 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Module Name
XWorm yu august.exe
Full Name
XWorm yu august.exe
EntryPoint
System.Void Stub.Main::Main()
Scope Name
XWorm yu august.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XWorm yu august
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
197
Main Method
System.Void Stub.Main::Main()
Main IL Instruction Count
64
Main IL
ldsfld System.Int32 Settings::Sleep
ldc.i4 1000
mul.ovf <null>
call System.Void System.Threading.Thread::Sleep(System.Int32)
ldsfld System.String Settings::Hosts
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Hosts
ldsfld System.String Settings::Port
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Port
ldsfld System.String Settings::KEY
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::KEY
ldsfld System.String Settings::SPL
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::SPL
ldsfld System.String Settings::Groub
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::Groub
ldsfld System.String Settings::USBNM
call System.Object Stub.AlgorithmAES::Decrypt(System.String)
call System.String Microsoft.VisualBasic.CompilerServices.Conversions::ToString(System.Object)
stsfld System.String Settings::USBNM
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
dup <null>
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::SetProjectError(System.Exception)
stloc.2 <null>
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Microsoft.VisualBasic.CompilerServices.ProjectData::ClearProjectError()
leave.s IL_009E: call System.Boolean Stub.Helper::CreateMutex()
call System.Boolean Stub.Helper::CreateMutex()
brtrue.s IL_00AB: call System.Void Stub.Main::Exclusion()
ldc.i4.0 <null>
call System.Void System.Environment::Exit(System.Int32)
call System.Void Stub.Main::Exclusion()
call System.Void Stub.Helper::PreventSleep()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__1()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
callvirt System.Void System.Threading.Thread::Start()
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__2()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.0 <null>
ldnull <null>
ldftn System.Void Stub.Main::_Lambda$__3()
newobj System.Void System.Threading.ThreadStart::.ctor(System.Object,System.IntPtr)
newobj System.Void System.Threading.Thread::.ctor(System.Threading.ThreadStart)
stloc.1 <null>
ldloc.0 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Start()
ldloc.1 <null>
callvirt System.Void System.Threading.Thread::Join()
ret <null>
Mutex MUTEXmalicious
U3dUchuhuhuhuhuhuhu
CnC CNCmalicious
155.huhuhuhuhuhuhu
Port PORTmalicious
1huhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Config. Field Value
Mutex U3dUchuhuhuhuhuhuhu
Hosts 155.huhuhuhuhuhuhu
Port 1huhuhuhu
KEY <V7PVhuhuhuhuhuhuhu
USBNM <Xwhuhuhuhu
family xhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Mutex MUTEXmalicious
U3dUchuhuhuhuhuhuhu
d7e149f1ca913d1858ddabfdd1d99225
CnC CNCmalicious
155.huhuhuhuhuhuhu
d7e149f1ca913d1858ddabfdd1d99225
Port PORTmalicious
1huhuhuhu
d7e149f1ca913d1858ddabfdd1d99225
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙