Malicious
Malicious

1.exe

PE Executable
|
MD5: dbdfd9ab774d8fa5a56718b1fae7bc95
|
Size: 279.04 KB
|
application/x-dosexec


Print
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
dbdfd9ab774d8fa5a56718b1fae7bc95
Sha1
df4c5c42e6b8d3c7324a34a2b017f362d9213558
Sha256
604c471648621880aeceac0534190b14e8c3ea05d4bc5bb95a8e777dd82e65aa
Sha384
67bffe054c88a26462519fe997c30d8bc540d7ae5b45b2ee5b62d2e946c88ab0ba74f10b6b9620e21e58f2e06f4f1848
Sha512
d3478dd32f89105cd62997f539961bb69a7eb08ca614f9185c29a32cb96f3dbc87638fea6eb09717ad67696d5aab1a39373aaddf0fd0c057ea6787346d7a31c8
SSDeep
3072:ne/3hGz8Su8ucwsy7vf7Qy63S9scCh4slxWsr7i9W3WWsZHpV0iukwEEfzqygF/S:n6xqucZy7vf8f3oMRxb/3W1Hp91Gq
TLSH
83546B6136A2CD7AD68020FF5C9DAABE1F1B889B6F8496E3B4945C4D5CB03D74231F41

PeID

Microsoft Visual C++ v6.0 DLL
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.00cfg
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0001
ID:1033
Malware Configuration - Vidar Config. Remote Dll Download #1
Config. Field
Value
C2

https://t.me/m08mbk

Botnet

hac22tl

UserAgent

Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:136.0) Gecko/20100101 Firefox/136.0

[Configuration Offset]

0x00038800

Malware Configuration - Vidar Config. Remote Dll Download #2
Config. Field
Value
C2

https://steamcommunity.com/profiles/76561199820567237

Botnet

hac22tl

UserAgent

Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:136.0) Gecko/20100101 Firefox/136.0

[Configuration Offset]

0x00038B00

Malware Configuration - Vidar Config. Remote Dll Download #3
Config. Field
Value
C2

https://t.me/m08mbk

Botnet

hac22tl

UserAgent

Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:136.0) Gecko/20100101 Firefox/136.0

[Configuration Offset]

0x00038E00

Malware Configuration - Vidar Config. Remote Dll Download #4
Config. Field
Value
C2

https://steamcommunity.com/profiles/76561199820567237

Botnet

hac22tl

UserAgent

Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:136.0) Gecko/20100101 Firefox/136.0

[Configuration Offset]

0x00039100

Malware Configuration - Vidar Config. Remote Dll Download #5
Config. Field
Value
C2

https://t.me/m08mbk

Botnet

hac22tl

UserAgent

Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:136.0) Gecko/20100101 Firefox/136.0

[Configuration Offset]

0x00039400

Malware Configuration - Vidar Config. Remote Dll Download #6
Config. Field
Value
C2

https://steamcommunity.com/profiles/76561199820567237

Botnet

hac22tl

UserAgent

Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:136.0) Gecko/20100101 Firefox/136.0

[Configuration Offset]

0x00039700

Malware Configuration - Vidar Config. Remote Dll Download #7
Config. Field
Value
C2

https://t.me/m08mbk

Botnet

hac22tl

UserAgent

Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:136.0) Gecko/20100101 Firefox/136.0

[Configuration Offset]

0x00039A00

1.exe (279.04 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙